Show filters
506 Total Results
Displaying 311-320 of 506
Sort by:
Attacker Value
Unknown

CVE-2019-17602

Disclosure Date: October 15, 2019 (last updated November 27, 2024)
An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated.
Attacker Value
Unknown

CVE-2019-17112

Disclosure Date: October 09, 2019 (last updated November 27, 2024)
An issue was discovered in Zoho ManageEngine DataSecurity Plus before 5.0.1 5012. An exposed service allows a basic user ("Operator" access level) to access the configuration file of the mail server (except for the password).
Attacker Value
Unknown

CVE-2019-19649

Disclosure Date: August 28, 2019 (last updated November 27, 2024)
Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function.
Attacker Value
Unknown

CVE-2019-19650

Disclosure Date: August 28, 2019 (last updated November 27, 2024)
Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet agentid parameter to the Agent.java process function.
Attacker Value
Unknown

CVE-2019-15645

Disclosure Date: August 27, 2019 (last updated November 27, 2024)
The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF.
0
Attacker Value
Unknown

CVE-2019-15644

Disclosure Date: August 27, 2019 (last updated November 27, 2024)
The zoho-salesiq plugin before 1.0.9 for WordPress has stored XSS.
0
Attacker Value
Unknown

CVE-2019-15045

Disclosure Date: August 21, 2019 (last updated November 08, 2023)
AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality
0
Attacker Value
Unknown

CVE-2019-15105

Disclosure Date: August 16, 2019 (last updated November 27, 2024)
An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute Program Action(s)" feature.
0
Attacker Value
Unknown

CVE-2019-15104

Disclosure Date: August 16, 2019 (last updated November 27, 2024)
An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute Program Action(s)" feature.
0
Attacker Value
Unknown

CVE-2019-15106

Disclosure Date: August 16, 2019 (last updated November 27, 2024)
An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on the server. The "username+'@opm' string is used for the password. For example, if the username is admin, the password is admin@opm.
0