Show filters
38 Total Results
Displaying 21-30 of 38
Sort by:
Attacker Value
Unknown
CVE-2019-7423
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/editProfile.jsp" file in the userName parameter.
0
Attacker Value
Unknown
CVE-2019-7422
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/addMailSettings.jsp" file in the gF parameter.
0
Attacker Value
Unknown
CVE-2019-7424
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/index.jsp" file in the view GET parameter or any of these POST parameters: autorefTime, section, snapshot, viewOpt, viewAll, view, or groupSelName. The latter is related to CVE-2009-3903.
0
Attacker Value
Unknown
CVE-2018-12997
Disclosure Date: June 29, 2018 (last updated December 08, 2023)
Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows attackers to read certain files on the web server without login by sending a specially crafted request to the server with the operation=copyfile&fileName= substring.
0
Attacker Value
Unknown
CVE-2018-12998
Disclosure Date: June 29, 2018 (last updated December 08, 2023)
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows remote attackers to inject arbitrary web script or HTML via the parameter 'operation' to /servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet.
0
Attacker Value
Unknown
CVE-2018-10803
Disclosure Date: May 10, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the add credentials functionality in Zoho ManageEngine NetFlow Analyzer v12.3 before 12.3.125 (build 123125) allows remote attackers to inject arbitrary web script or HTML via a crafted description value. This can be exploited through CSRF.
0
Attacker Value
Unknown
CVE-2015-4418
Disclosure Date: June 09, 2015 (last updated October 05, 2023)
Zoho NetFlow Analyzer build 10250 and earlier does not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.
0
Attacker Value
Unknown
CVE-2015-2961
Disclosure Date: June 09, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in Zoho NetFlow Analyzer build 10250 and earlier allows remote attackers to hijack the authentication of administrators.
0
Attacker Value
Unknown
CVE-2015-2959
Disclosure Date: June 09, 2015 (last updated October 05, 2023)
Zoho NetFlow Analyzer build 10250 and earlier does not check for administrative authorization, which allows remote attackers to obtain sensitive information, modify passwords, or remove accounts by leveraging the guest role.
0
Attacker Value
Unknown
CVE-2015-2960
Disclosure Date: June 09, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Zoho NetFlow Analyzer build 10250 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0