Show filters
45 Total Results
Displaying 41-45 of 45
Sort by:
Attacker Value
Unknown

CVE-2020-11531

Disclosure Date: May 08, 2020 (last updated February 21, 2025)
The DataEngine Xnode Server application in Zoho ManageEngine DataSecurity Plus prior to 6.0.1 does not validate the database schema name when handling a DR-SCHEMA-SYNC request. This allows an authenticated attacker to execute code in the context of the product by writing a JSP file to the webroot directory via directory traversal.
Attacker Value
Unknown

CVE-2020-11532

Disclosure Date: May 08, 2020 (last updated February 21, 2025)
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attacker to bypass authentication for this server and execute all operations in the context of admin user.
Attacker Value
Unknown

CVE-2018-19118

Disclosure Date: December 13, 2018 (last updated November 27, 2024)
Zoho ManageEngine ADAudit before 5.1 build 5120 allows remote attackers to cause a denial of service (stack-based buffer overflow) via the 'Domain Name' field when adding a new domain.
0
Attacker Value
Unknown

CVE-2018-10466

Disclosure Date: May 29, 2018 (last updated November 26, 2024)
Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection.
0
Attacker Value
Unknown

CVE-2010-2049

Disclosure Date: May 25, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in jsp/audit/reports/ExportReport.jsp in ManageEngine ADAudit Plus 4.0.0 build 4043 allows remote attackers to inject arbitrary web script or HTML via the reportList parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0