Show filters
506 Total Results
Displaying 301-310 of 506
Sort by:
Attacker Value
Unknown

CVE-2020-6843

Disclosure Date: January 23, 2020 (last updated February 21, 2025)
Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007 allows XSS. This issue was fixed in version 11.0 Build 11010, SD-83959.
Attacker Value
Unknown

CVE-2014-5007

Disclosure Date: January 17, 2020 (last updated February 21, 2025)
Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90055 allows remote attackers to write to and execute arbitrary files as SYSTEM via a .. (dot dot) in the filename parameter.
Attacker Value
Unknown

CVE-2014-6038

Disclosure Date: January 13, 2020 (last updated February 21, 2025)
Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLog Analyzer 10.0 Build 10000.
Attacker Value
Unknown

CVE-2014-6039

Disclosure Date: January 13, 2020 (last updated February 21, 2025)
ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000.
Attacker Value
Unknown

CVE-2019-19475

Disclosure Date: January 10, 2020 (last updated February 21, 2025)
An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is prone to attack due to lack of file permission security. The malicious users who are in “Authenticated Users” group can exploit privilege escalation and modify PostgreSQL configuration to execute arbitrary command to escalate and gain full system privilege user access and rights over the system.
Attacker Value
Unknown

CVE-2019-7162

Disclosure Date: December 31, 2019 (last updated November 27, 2024)
An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.6 Build 5607. An exposed service allows an unauthenticated person to retrieve internal information from the system and modify the product installation.
Attacker Value
Unknown

CVE-2019-19774

Disclosure Date: December 13, 2019 (last updated November 27, 2024)
An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it is possible to bypass the security restrictions that prevent even administrative users from viewing credential data stored in the database, and recover the MD5 hashes of the accounts used to authenticate the ManageEngine platform to the managed machines on the network (most often administrative accounts). Specifically, this bypasses these restrictions: a query cannot mention password, and a query result cannot have a password column.
Attacker Value
Unknown

CVE-2019-19306

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName.
Attacker Value
Unknown

CVE-2019-17421

Disclosure Date: November 21, 2019 (last updated November 27, 2024)
Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a malicious payload.
Attacker Value
Unknown

CVE-2019-18411

Disclosure Date: November 06, 2019 (last updated November 27, 2024)
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the reset password function and control the system to send the authentication code back to the channel that the attackers own.