Show filters
506 Total Results
Displaying 401-410 of 506
Sort by:
Attacker Value
Unknown

CVE-2018-15169

Disclosure Date: August 08, 2018 (last updated November 27, 2024)
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to inject arbitrary web script or HTML via the /deleteMO.do method parameter.
0
Attacker Value
Unknown

CVE-2018-15168

Disclosure Date: August 08, 2018 (last updated November 27, 2024)
A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplaynames.do?method=editDisplaynames GET request.
0
Attacker Value
Unknown

CVE-2018-11716

Disclosure Date: July 16, 2018 (last updated November 27, 2024)
An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled devices, cleartext passwords, patching level, etc.) via a GET request on port 8022, 8443, or 8444.
0
Attacker Value
Unknown

CVE-2018-11717

Disclosure Date: July 16, 2018 (last updated November 27, 2024)
An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base64 encoded Password/Username of AD accounts, the cleartext Password/Username and mail settings of the EAS account (an AD account used to send mail), the cleartext password of recovery_password of Android devices, the cleartext password of account "set", the location of devices enrolled in the platform (with UUID and information related to the name of the person at the location), critical information about all enrolled devices such as Serial Number, UUID, Model, Name, and auth_session_token (usable to spoof a terminal identity on the platform), etc.
0
Attacker Value
Unknown

ManageEngine Applications Manager 12 and 13 is vulnerable to privilege escalati…

Disclosure Date: July 13, 2018 (last updated November 27, 2024)
ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem and read the system files, including Applications Manager configuration, stored private keys, etc. By default Application Manager is running with administrative privileges, therefore it is possible to access every directory on the underlying operating system.
0
Attacker Value
Unknown

ManageEngine Applications Manager 12 and 13, allows unserialization of unsafe J…

Disclosure Date: July 13, 2018 (last updated November 27, 2024)
ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by remote user without authentication and it allows to execute remote code compromising the application as well as the operating system. As Application Manager's RMI registry is running with privileges of system administrator, by exploiting this vulnerability an attacker gains highest privileges on the underlying operating system.
0
Attacker Value
Unknown

ManageEngine Applications Manager 12 and 13 is vulnerable to privilege escalati…

Disclosure Date: July 13, 2018 (last updated November 27, 2024)
In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own group, i.e. changing their group to one with higher privileges like "ADMIN". A user is also able to change properties of another user, e.g. change another user's password.
0
Attacker Value
Unknown

CVE-2018-10076

Disclosure Date: July 02, 2018 (last updated November 26, 2024)
An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. A Cross-Site Scripting vulnerability allows a remote attacker to inject arbitrary web script or HTML via the search functionality (the search box of the Dashboard).
0
Attacker Value
Unknown

CVE-2018-10075

Disclosure Date: July 02, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer 11.12 allows remote attackers to inject arbitrary web script or HTML via the import logs feature.
0
Attacker Value
Unknown

CVE-2018-13050

Disclosure Date: July 02, 2018 (last updated November 26, 2024)
A SQL Injection vulnerability exists in Zoho ManageEngine Applications Manager 13.x before build 13800 via the j_username parameter in a /j_security_check POST request.
0