Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2018-5339
Disclosure Date: April 18, 2018 (last updated November 26, 2024)
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions.
0
Attacker Value
Unknown
CVE-2018-5337
Disclosure Date: April 18, 2018 (last updated November 26, 2024)
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NAME field when modifying existing scripts.
0
Attacker Value
Unknown
CVE-2018-5340
Disclosure Date: April 18, 2018 (last updated November 26, 2024)
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: database access using a superuser account (specifically, an account with permission to write to the filesystem via SQL queries).
0
Attacker Value
Unknown
CVE-2018-5342
Disclosure Date: April 18, 2018 (last updated November 26, 2024)
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: network services (Desktop Central and PostgreSQL) running with a superuser account.
0
Attacker Value
Unknown
CVE-2018-5341
Disclosure Date: April 18, 2018 (last updated November 26, 2024)
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploading and modifying scripts.
0
Attacker Value
Unknown
CVE-2018-5338
Disclosure Date: April 18, 2018 (last updated November 26, 2024)
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanism.
0