Show filters
506 Total Results
Displaying 291-300 of 506
Sort by:
Attacker Value
Unknown

CVE-2020-9346

Disclosure Date: March 16, 2020 (last updated February 21, 2025)
Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role.
Attacker Value
Unknown

CVE-2019-19799

Disclosure Date: March 13, 2020 (last updated February 21, 2025)
Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet.
Attacker Value
Unknown

CVE-2020-10541

Disclosure Date: March 13, 2020 (last updated November 27, 2024)
Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1 API request. This was fixed in 12.5.108.
Attacker Value
Unknown

CVE-2020-8540

Disclosure Date: March 11, 2020 (last updated February 21, 2025)
An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
Attacker Value
Unknown

CVE-2016-1159

Disclosure Date: March 09, 2020 (last updated February 21, 2025)
In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry password history) via a vulnerable hidden service.
Attacker Value
Unknown

CVE-2019-20474

Disclosure Date: February 17, 2020 (last updated February 21, 2025)
An issue was discovered in Zoho ManageEngine Remote Access Plus 10.0.447. The service to test the mail-server configuration suffers from an authorization issue allowing a user with the Guest role (read-only access) to use and abuse it. One of the abuses allows performing network and port scan operations of the localhost or the hosts on the same network segment, aka SSRF.
Attacker Value
Unknown

CVE-2014-7863

Disclosure Date: February 08, 2020 (last updated February 21, 2025)
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and remote authenticated users to (1) read arbitrary files via the fileName parameter in a copyfile operation or (2) obtain sensitive information via a directory listing in a listdirectory operation to servlet/FailOverHelperServlet.
Attacker Value
Unknown

CVE-2019-19800

Disclosure Date: February 06, 2020 (last updated February 21, 2025)
Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.
Attacker Value
Unknown

CVE-2020-8422

Disclosure Date: January 31, 2020 (last updated November 27, 2024)
An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 10.0.450. A user with the Guest role can extract the collection of all defined credentials of remote machines: the credential name, credential type, user name, domain/workgroup name, and description (but not the password).
Attacker Value
Unknown

CVE-2013-7390

Disclosure Date: January 27, 2020 (last updated February 21, 2025)
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the webroot.