Zohocorp

Manageengine Eventlog Analyzer

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.48%
  • Veröffentlicht 13.03.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 04:12:05

Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Exploit
  • EPSS 0.47%
  • Veröffentlicht 27.07.2017 06:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Multiple Persistent cross-site scripting (XSS) vulnerabilities in Event log parsing and Display functions in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML via syslog.

Exploit
  • EPSS 1.66%
  • Veröffentlicht 27.07.2017 06:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the password is represented in a cookie with a reversibl...

Exploit
  • EPSS 0.47%
  • Veröffentlicht 27.07.2017 06:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Multiple Reflective cross-site scripting (XSS) vulnerabilities in search and display of event data in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML, as demonstrated by the fName param...

Exploit
  • EPSS 82.23%
  • Veröffentlicht 28.09.2015 15:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions and execute arbitrary SQL commands via an allowed query followed by a disallowed one in the query parameter to event/runQuery.do,...

Exploit
  • EPSS 81.73%
  • Veröffentlicht 26.10.2014 19:55:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 allows remote attackers to execute arbitrary code by uploading a ZIP file which contains an executable file with .. ...

Exploit
  • EPSS 5.8%
  • Veröffentlicht 11.09.2014 15:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote authenticated users to obtain access to the database via a direct request to event/runQuery.do. Fixed...

  • EPSS 0.45%
  • Veröffentlicht 29.08.2014 13:55:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple cross-site scripting (XSS) vulnerabilities in event/index2.do in ManageEngine EventLog Analyzer before 9.0 build 9002 allow remote attackers to inject arbitrary web script or HTML via the (1) width, (2) height, (3) url, (4) helpP, (5) tab, (...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 25.07.2014 19:55:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine EventLog Analyzer 9 build 9000 allows remote attackers to inject arbitrary web script or HTML via the j_username parameter to event/j_security_check. Fixed in Version 10 Build 10000.