Show filters
506 Total Results
Displaying 421-430 of 506
Sort by:
Attacker Value
Unknown
CVE-2018-5340
Disclosure Date: April 18, 2018 (last updated November 26, 2024)
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: database access using a superuser account (specifically, an account with permission to write to the filesystem via SQL queries).
0
Attacker Value
Unknown
CVE-2018-5342
Disclosure Date: April 18, 2018 (last updated November 26, 2024)
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: network services (Desktop Central and PostgreSQL) running with a superuser account.
0
Attacker Value
Unknown
CVE-2018-5341
Disclosure Date: April 18, 2018 (last updated November 26, 2024)
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploading and modifying scripts.
0
Attacker Value
Unknown
CVE-2018-5338
Disclosure Date: April 18, 2018 (last updated November 26, 2024)
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanism.
0
Attacker Value
Unknown
CVE-2018-9163
Disclosure Date: April 02, 2018 (last updated November 26, 2024)
A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) allows remote authenticated users (with Add New Technician permissions) to inject arbitrary web script or HTML via the loginName field to technicianAction.do.
0
Attacker Value
Unknown
CVE-2018-5799
Disclosure Date: March 30, 2018 (last updated November 26, 2024)
In Zoho ManageEngine ServiceDesk Plus before 9403, an XSS issue allows an attacker to run arbitrary JavaScript via a /api/request/?OPERATION_NAME= URI, aka SD-69139.
0
Attacker Value
Unknown
CVE-2018-8721
Disclosure Date: March 15, 2018 (last updated November 26, 2024)
Zoho ManageEngine EventLog Analyzer version 11.0 build 11000 has Stored XSS related to the index2.do?url=editAlertForm&tab=alert&alert=profile URI and the Edit Alert Profile screen
0
Attacker Value
Unknown
CVE-2018-8722
Disclosure Date: March 15, 2018 (last updated November 26, 2024)
Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026.
0
Attacker Value
Unknown
CVE-2018-7405
Disclosure Date: March 13, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2018-7890
Disclosure Date: March 08, 2018 (last updated November 26, 2024)
A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredential.do endpoint takes multiple user inputs and validates supplied credentials by accessing a specified system. This endpoint calls several internal classes, and then executes a PowerShell script. If the specified system is OfficeSharePointServer, then the username and password parameters to this script are not validated, leading to Command Injection.
0