Show filters
62 Total Results
Displaying 31-40 of 62
Sort by:
Attacker Value
Unknown

CVE-2019-17602

Disclosure Date: October 15, 2019 (last updated November 27, 2024)
An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated.
Attacker Value
Unknown

CVE-2019-15106

Disclosure Date: August 16, 2019 (last updated November 27, 2024)
An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on the server. The "username+'@opm' string is used for the password. For example, if the username is admin, the password is admin@opm.
0
Attacker Value
Unknown

CVE-2019-12133

Disclosure Date: June 18, 2019 (last updated November 27, 2024)
Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current directory upon system start. This will effectively allow non-privileged users to escalate privileges to NT AUTHORITY\SYSTEM. This affects Desktop Central 10.0.380, EventLog Analyzer 12.0.2, ServiceDesk Plus 10.0.0, SupportCenter Plus 8.1, O365 Manager Plus 4.0, Mobile Device Manager Plus 9.0.0, Patch Connect Plus 9.0.0, Vulnerability Manager Plus 9.0.0, Patch Manager Plus 9.0.0, OpManager 12.3, NetFlow Analyzer 11.0, OpUtils 11.0, Network Configuration Manager 11.0, FireWall 12.0, Key Manager Plus 5.6, Password Manager Pro 9.9, Analytics Plus 1.0, and Browser Security Plus.
0
Attacker Value
Unknown

CVE-2017-11559

Disclosure Date: May 23, 2019 (last updated November 27, 2024)
An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboard/gotoverviewlist" is vulnerable to a Blind SQL Injection attack.
0
Attacker Value
Unknown

CVE-2017-11560

Disclosure Date: May 23, 2019 (last updated November 27, 2024)
An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file. This HTML file is then rendered in various locations of the application. JavaScript inside the uploaded HTML is also interpreted by the application. Thus, an attacker can inject a malicious JavaScript payload inside the HTML file and upload it to the application.
0
Attacker Value
Unknown

CVE-2017-11561

Disclosure Date: May 23, 2019 (last updated November 27, 2024)
An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell.
0
Attacker Value
Unknown

CVE-2018-20338

Disclosure Date: December 21, 2018 (last updated November 27, 2024)
Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section.
0
Attacker Value
Unknown

CVE-2018-20339

Disclosure Date: December 21, 2018 (last updated November 27, 2024)
Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section.
0
Attacker Value
Unknown

CVE-2018-20173

Disclosure Date: December 17, 2018 (last updated November 27, 2024)
Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API.
0
Attacker Value
Unknown

CVE-2018-19921

Disclosure Date: December 06, 2018 (last updated November 27, 2024)
Zoho ManageEngine OpManager 12.3 before 123237 has XSS in the domain controller.
0