Show filters
146 Total Results
Displaying 71-80 of 146
Sort by:
Attacker Value
Unknown
CVE-2018-18980
Disclosure Date: November 06, 2018 (last updated November 27, 2024)
An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local files to an arbitrary remote FTP server.
0
Attacker Value
Unknown
CVE-2018-17051
Disclosure Date: September 14, 2018 (last updated November 27, 2024)
K-Net Cisco Configuration Manager through 2014-11-19 has XSS via devices.php.
0
Attacker Value
Unknown
CVE-2018-7077
Disclosure Date: August 14, 2018 (last updated November 27, 2024)
A security vulnerability in HPE XP P9000 Command View Advanced Edition (CVAE) Device Manager (DevMgr 8.5.0-00 and prior to 8.6.0-00), Configuration Manager (CM 8.5.0-00 and prior to 8.6.0-00) could be exploited to allow local and remote unauthorized access to sensitive information.
0
Attacker Value
Unknown
CVE-2018-12997
Disclosure Date: June 29, 2018 (last updated December 08, 2023)
Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows attackers to read certain files on the web server without login by sending a specially crafted request to the server with the operation=copyfile&fileName= substring.
0
Attacker Value
Unknown
CVE-2018-12998
Disclosure Date: June 29, 2018 (last updated December 08, 2023)
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows remote attackers to inject arbitrary web script or HTML via the parameter 'operation' to /servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet.
0
Attacker Value
Unknown
MFSBGN03803 rev.1 - UCMDB, Installation File Access Control Privilege Escalatio…
Disclosure Date: April 24, 2018 (last updated November 08, 2023)
Local Escalation of Privilege vulnerability to Micro Focus Universal CMDB, versions 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.00. The vulnerability could be remotely exploited to Local Escalation of Privilege.
0
Attacker Value
Unknown
CVE-2015-5016
Disclosure Date: March 27, 2018 (last updated November 26, 2024)
IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access restrictions and read arbitrary ticket worklog entries via unspecified vectors. IBM X-Force ID: 106460.
0
Attacker Value
Unknown
MFSBGN03798 rev.1 - Micro Focus Universal CMDB, Apache Struts Instance
Disclosure Date: February 22, 2018 (last updated November 08, 2023)
Arbitrary Code Execution vulnerability in Micro Focus Universal CMDB, version 4.10, 4.11, 4.12. This vulnerability could be remotely exploited to allow Arbitrary Code Execution.
0
Attacker Value
Unknown
CVE-2017-8947
Disclosure Date: February 15, 2018 (last updated November 26, 2024)
A Remote Code Execution vulnerability in HPE UCMDB version v10.10, v10.11, v10.20, v10.21, v10.22, v10.30, v10.31 was found.
0
Attacker Value
Unknown
CVE-2017-8017
Disclosure Date: October 11, 2017 (last updated November 26, 2024)
EMC Network Configuration Manager (NCM) 9.3.x, 9.4.0.x, 9.4.1.x, and 9.4.2.x is affected by a reflected cross-site scripting Vulnerability that could potentially be exploited by malicious users to compromise the affected system.
0