Show filters
506 Total Results
Displaying 451-460 of 506
Sort by:
Attacker Value
Unknown
CVE-2015-7781
Disclosure Date: June 27, 2017 (last updated November 26, 2024)
ManageEngine Firewall Analyzer before 8.0 does not restrict access permissions.
0
Attacker Value
Unknown
CVE-2017-7213
Disclosure Date: May 15, 2017 (last updated November 26, 2024)
Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-1161
Disclosure Date: April 20, 2017 (last updated November 26, 2024)
Cross-site request forgery (CSRF) vulnerability in ManageEngine Password Manager Pro before 8.5 (Build 8500).
0
Attacker Value
Unknown
CVE-2016-4888
Disclosure Date: April 14, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine ServiceDesk Plus before 9.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-4890
Disclosure Date: April 14, 2017 (last updated November 26, 2024)
ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive password information by leveraging access to a cookie.
0
Attacker Value
Unknown
CVE-2016-4889
Disclosure Date: April 14, 2017 (last updated November 26, 2024)
ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict access to unknown functions.
0
Attacker Value
Unknown
CVE-2016-6602
Disclosure Date: January 23, 2017 (last updated November 25, 2024)
ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartext passwords by leveraging access to WEB-INF/conf/securitydbData.xml. NOTE: this issue can be combined with CVE-2016-6601 for a remote exploit.
0
Attacker Value
Unknown
CVE-2016-6600
Disclosure Date: January 23, 2017 (last updated November 25, 2024)
Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and execute arbitrary JSP files via a .. (dot dot) in the fileName parameter to servlets/FileUploadServlet.
0
Attacker Value
Unknown
CVE-2016-6603
Disclosure Date: January 23, 2017 (last updated November 25, 2024)
ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.
0
Attacker Value
Unknown
CVE-2016-6601
Disclosure Date: January 23, 2017 (last updated November 25, 2024)
Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter to servlets/FetchFile.
0