CVE-2018-7405
- EPSS 1.3%
- Veröffentlicht 13.03.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:05
Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2017-11687
- EPSS 1.27%
- Veröffentlicht 27.07.2017 06:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Multiple Persistent cross-site scripting (XSS) vulnerabilities in Event log parsing and Display functions in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML via syslog.
CVE-2017-11686
- EPSS 2.29%
- Veröffentlicht 27.07.2017 06:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the password is represented in a cookie with a reversibl...
CVE-2017-11685
- EPSS 1.27%
- Veröffentlicht 27.07.2017 06:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Multiple Reflective cross-site scripting (XSS) vulnerabilities in search and display of event data in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML, as demonstrated by the fName param...
CVE-2015-7387
- EPSS 80.19%
- Veröffentlicht 28.09.2015 15:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions and execute arbitrary SQL commands via an allowed query followed by a disallowed one in the query parameter to event/runQuery.do,...
CVE-2014-6037
- EPSS 84.18%
- Veröffentlicht 26.10.2014 19:55:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 allows remote attackers to execute arbitrary code by uploading a ZIP file which contains an executable file with .. ...
CVE-2014-6043
- EPSS 12.8%
- Veröffentlicht 11.09.2014 15:55:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote authenticated users to obtain access to the database via a direct request to event/runQuery.do. Fixed...
CVE-2014-4930
- EPSS 3.63%
- Veröffentlicht 29.08.2014 13:55:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple cross-site scripting (XSS) vulnerabilities in event/index2.do in ManageEngine EventLog Analyzer before 9.0 build 9002 allow remote attackers to inject arbitrary web script or HTML via the (1) width, (2) height, (3) url, (4) helpP, (5) tab, (...
CVE-2014-5103
- EPSS 3.5%
- Veröffentlicht 25.07.2014 19:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine EventLog Analyzer 9 build 9000 allows remote attackers to inject arbitrary web script or HTML via the j_username parameter to event/j_security_check. Fixed in Version 10 Build 10000.