Show filters
506 Total Results
Displaying 501-506 of 506
Sort by:
Attacker Value
Unknown
CVE-2011-5105
Disclosure Date: August 23, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in ZOHO ManageEngine ADSelfService Plus 4.5 Build 4521 allow remote attackers to inject arbitrary web script or HTML via the (1) searchType and (2) searchString parameters, a different vulnerability than CVE-2010-3274.
0
Attacker Value
Unknown
CVE-2010-5050
Disclosure Date: November 23, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in jsp/admin/tools/remote_share.jsp in ManageEngine ADManager Plus 4.4.0 allows remote attackers to inject arbitrary web script or HTML via the computerName parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2010-3272
Disclosure Date: February 17, 2011 (last updated October 04, 2023)
accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 makes it easier for remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, via a modified (1) Hide_Captcha or (2) quesList parameter in a validateAll action.
0
Attacker Value
Unknown
CVE-2010-3274
Disclosure Date: February 17, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in the Employee Search Engine in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allow remote attackers to inject arbitrary web script or HTML via the searchString parameter in a (1) showList or (2) Search action.
0
Attacker Value
Unknown
CVE-2010-3273
Disclosure Date: February 17, 2011 (last updated October 04, 2023)
ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allows remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, by providing a user id to accounts/ValidateUser, and then providing a new password to accounts/ResetResult.
0
Attacker Value
Unknown
CVE-2009-2155
Disclosure Date: June 22, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in report/ReportViewAction.do in WebNMS Free Edition 5 allows remote attackers to inject arbitrary web script or HTML via the type parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0