Show filters
506 Total Results
Displaying 341-350 of 506
Sort by:
Attacker Value
Unknown
CVE-2019-12543
Disclosure Date: June 05, 2019 (last updated November 27, 2024)
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter.
0
Attacker Value
Unknown
CVE-2019-8346
Disclosure Date: May 24, 2019 (last updated November 27, 2024)
In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated manipulation of the JavaScript code by injecting the HTTP form parameter adscsrf. An attacker can use this to capture a user's AD self-service password reset and MFA token.
0
Attacker Value
Unknown
CVE-2017-11559
Disclosure Date: May 23, 2019 (last updated November 27, 2024)
An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboard/gotoverviewlist" is vulnerable to a Blind SQL Injection attack.
0
Attacker Value
Unknown
CVE-2017-11560
Disclosure Date: May 23, 2019 (last updated November 27, 2024)
An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file. This HTML file is then rendered in various locations of the application. JavaScript inside the uploaded HTML is also interpreted by the application. Thus, an attacker can inject a malicious JavaScript payload inside the HTML file and upload it to the application.
0
Attacker Value
Unknown
CVE-2017-11557
Disclosure Date: May 23, 2019 (last updated November 27, 2024)
An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names and usernames used in a company's network environment via a userconfiguration.do?method=editUser request.
0
Attacker Value
Unknown
CVE-2017-11738
Disclosure Date: May 23, 2019 (last updated November 27, 2024)
In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack.
0
Attacker Value
Unknown
CVE-2017-11740
Disclosure Date: May 23, 2019 (last updated November 27, 2024)
In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse this functionality by uploading a malicious script that can be executed on the remote system.
0
Attacker Value
Unknown
CVE-2017-11561
Disclosure Date: May 23, 2019 (last updated November 27, 2024)
An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell.
0
Attacker Value
Unknown
CVE-2017-11739
Disclosure Date: May 23, 2019 (last updated November 27, 2024)
In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard. This widget can be a "Utility Widget" with a "Custom HTML or Text" field. Once this widget is created, it will be loaded on the dashboard where it was added. An attacker can abuse this functionality by creating a "Utility Widget" that contains malicious JavaScript code, aka XSS.
0
Attacker Value
Unknown
CVE-2019-12252
Disclosure Date: May 21, 2019 (last updated November 27, 2024)
In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail¬ifyTo=SOLFORWARD&id= substring.
0