Show filters
54 Total Results
Displaying 31-40 of 54
Sort by:
Attacker Value
Unknown

CVE-2018-13412

Disclosure Date: September 12, 2018 (last updated November 27, 2024)
An issue was discovered in the Self Service Portal in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version.
0
Attacker Value
Unknown

CVE-2018-11716

Disclosure Date: July 16, 2018 (last updated November 27, 2024)
An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled devices, cleartext passwords, patching level, etc.) via a GET request on port 8022, 8443, or 8444.
0
Attacker Value
Unknown

CVE-2018-11717

Disclosure Date: July 16, 2018 (last updated November 27, 2024)
An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base64 encoded Password/Username of AD accounts, the cleartext Password/Username and mail settings of the EAS account (an AD account used to send mail), the cleartext password of recovery_password of Android devices, the cleartext password of account "set", the location of devices enrolled in the platform (with UUID and information related to the name of the person at the location), critical information about all enrolled devices such as Serial Number, UUID, Model, Name, and auth_session_token (usable to spoof a terminal identity on the platform), etc.
0
Attacker Value
Unknown

CVE-2018-12999

Disclosure Date: June 29, 2018 (last updated November 26, 2024)
Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web server without login by sending a specially crafted request to the server with a computerName=../ substring to the /agenttrayicon URI.
0
Attacker Value
Unknown

CVE-2018-5339

Disclosure Date: April 18, 2018 (last updated November 26, 2024)
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions.
0
Attacker Value
Unknown

CVE-2018-5337

Disclosure Date: April 18, 2018 (last updated November 26, 2024)
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NAME field when modifying existing scripts.
0
Attacker Value
Unknown

CVE-2018-5340

Disclosure Date: April 18, 2018 (last updated November 26, 2024)
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: database access using a superuser account (specifically, an account with permission to write to the filesystem via SQL queries).
0
Attacker Value
Unknown

CVE-2018-5342

Disclosure Date: April 18, 2018 (last updated November 26, 2024)
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: network services (Desktop Central and PostgreSQL) running with a superuser account.
0
Attacker Value
Unknown

CVE-2018-5341

Disclosure Date: April 18, 2018 (last updated November 26, 2024)
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploading and modifying scripts.
0
Attacker Value
Unknown

CVE-2018-5338

Disclosure Date: April 18, 2018 (last updated November 26, 2024)
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanism.
0