Zohocorp

Manageengine Desktop Central

48 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Veröffentlicht 03.11.2023 11:15:08
  • Zuletzt bearbeitet 21.11.2024 08:35:56

A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerability could allow an authenticated attacker to launch targeted attacks, such as a cross-port attack, ...

  • EPSS 0.68%
  • Veröffentlicht 03.11.2023 11:15:08
  • Zuletzt bearbeitet 21.11.2024 08:35:56

A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName para...

  • EPSS 0.68%
  • Veröffentlicht 03.11.2023 11:15:08
  • Zuletzt bearbeitet 21.11.2024 08:35:56

A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName para...

Exploit
  • EPSS 1.3%
  • Veröffentlicht 25.02.2023 21:15:10
  • Zuletzt bearbeitet 11.03.2025 21:15:39

Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker could upload arbitrary code that would be executed when Desktop Central...

  • EPSS 43.57%
  • Veröffentlicht 02.03.2022 15:15:08
  • Zuletzt bearbeitet 21.11.2024 06:49:15

Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses.

  • EPSS 2.95%
  • Veröffentlicht 28.01.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:49:23

Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password.

  • EPSS 38.57%
  • Veröffentlicht 18.01.2022 10:15:08
  • Zuletzt bearbeitet 21.11.2024 06:31:31

Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server.

  • EPSS 0.31%
  • Veröffentlicht 10.01.2022 14:11:32
  • Zuletzt bearbeitet 21.11.2024 06:33:43

Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Reports page.

  • EPSS 0.1%
  • Veröffentlicht 10.01.2022 14:11:32
  • Zuletzt bearbeitet 21.11.2024 06:33:43

Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but this file's path might not be properly defined.

  • EPSS 9.82%
  • Veröffentlicht 10.01.2022 14:11:31
  • Zuletzt bearbeitet 21.11.2024 06:33:43

Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete access to the Reports module.