Show filters
506 Total Results
Displaying 431-440 of 506
Sort by:
Attacker Value
Unknown
CVE-2017-16924
Disclosure Date: February 19, 2018 (last updated November 26, 2024)
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/collections/##/usermgmt.xml URL, as demonstrated by passwords and Wi-Fi keys. This is fixed in build 100157.
0
Attacker Value
Unknown
CVE-2017-17552
Disclosure Date: February 07, 2018 (last updated November 26, 2024)
/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted.
0
Attacker Value
Unknown
CVE-2014-7862
Disclosure Date: January 04, 2018 (last updated November 26, 2024)
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.
0
Attacker Value
Unknown
CVE-2017-17698
Disclosure Date: December 15, 2017 (last updated November 26, 2024)
Zoho ManageEngine Password Manager Pro 9 before 9.4 (9400) has reflected XSS in SearchResult.ec and BulkAccessControlView.ec.
0
Attacker Value
Unknown
CVE-2017-16847
Disclosure Date: November 16, 2017 (last updated November 26, 2024)
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a showPlasmaView action.
0
Attacker Value
Unknown
CVE-2017-16848
Disclosure Date: November 16, 2017 (last updated November 26, 2024)
Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter.
0
Attacker Value
Unknown
CVE-2017-16850
Disclosure Date: November 16, 2017 (last updated November 26, 2024)
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfiles action.
0
Attacker Value
Unknown
CVE-2017-16846
Disclosure Date: November 16, 2017 (last updated November 26, 2024)
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter.
0
Attacker Value
Unknown
CVE-2017-16849
Disclosure Date: November 16, 2017 (last updated November 26, 2024)
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoard forpage parameter.
0
Attacker Value
Unknown
CVE-2017-16851
Disclosure Date: November 16, 2017 (last updated November 26, 2024)
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter.
0