Show filters
57 Total Results
Displaying 31-40 of 57
Sort by:
Attacker Value
Unknown
CVE-2017-11560
Disclosure Date: May 23, 2019 (last updated November 27, 2024)
An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file. This HTML file is then rendered in various locations of the application. JavaScript inside the uploaded HTML is also interpreted by the application. Thus, an attacker can inject a malicious JavaScript payload inside the HTML file and upload it to the application.
0
Attacker Value
Unknown
CVE-2017-11561
Disclosure Date: May 23, 2019 (last updated November 27, 2024)
An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell.
0
Attacker Value
Unknown
CVE-2018-20338
Disclosure Date: December 21, 2018 (last updated November 27, 2024)
Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section.
0
Attacker Value
Unknown
CVE-2018-20339
Disclosure Date: December 21, 2018 (last updated November 27, 2024)
Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section.
0
Attacker Value
Unknown
CVE-2018-20173
Disclosure Date: December 17, 2018 (last updated November 27, 2024)
Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API.
0
Attacker Value
Unknown
CVE-2018-19921
Disclosure Date: December 06, 2018 (last updated November 27, 2024)
Zoho ManageEngine OpManager 12.3 before 123237 has XSS in the domain controller.
0
Attacker Value
Unknown
CVE-2018-18716
Disclosure Date: November 20, 2018 (last updated November 27, 2024)
Zoho ManageEngine OpManager 12.3 before 123219 has a Self XSS Vulnerability.
0
Attacker Value
Unknown
CVE-2018-18715
Disclosure Date: November 20, 2018 (last updated November 27, 2024)
Zoho ManageEngine OpManager 12.3 before 123219 has stored XSS.
0
Attacker Value
Unknown
CVE-2018-19288
Disclosure Date: November 15, 2018 (last updated November 27, 2024)
Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API.
0
Attacker Value
Unknown
CVE-2018-18980
Disclosure Date: November 06, 2018 (last updated November 27, 2024)
An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local files to an arbitrary remote FTP server.
0