Show filters
506 Total Results
Displaying 501-506 of 506
Sort by:
Attacker Value
Unknown

CVE-2011-5105

Disclosure Date: August 23, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in ZOHO ManageEngine ADSelfService Plus 4.5 Build 4521 allow remote attackers to inject arbitrary web script or HTML via the (1) searchType and (2) searchString parameters, a different vulnerability than CVE-2010-3274.
0
Attacker Value
Unknown

CVE-2010-5050

Disclosure Date: November 23, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in jsp/admin/tools/remote_share.jsp in ManageEngine ADManager Plus 4.4.0 allows remote attackers to inject arbitrary web script or HTML via the computerName parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2010-3272

Disclosure Date: February 17, 2011 (last updated October 04, 2023)
accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 makes it easier for remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, via a modified (1) Hide_Captcha or (2) quesList parameter in a validateAll action.
0
Attacker Value
Unknown

CVE-2010-3274

Disclosure Date: February 17, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in the Employee Search Engine in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allow remote attackers to inject arbitrary web script or HTML via the searchString parameter in a (1) showList or (2) Search action.
0
Attacker Value
Unknown

CVE-2010-3273

Disclosure Date: February 17, 2011 (last updated October 04, 2023)
ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allows remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, by providing a user id to accounts/ValidateUser, and then providing a new password to accounts/ResetResult.
0
Attacker Value
Unknown

CVE-2009-2155

Disclosure Date: June 22, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in report/ReportViewAction.do in WebNMS Free Edition 5 allows remote attackers to inject arbitrary web script or HTML via the type parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0