CVE-2018-11717
- EPSS 9.61%
- Published 16.07.2018 14:29:00
- Last modified 21.11.2024 03:43:53
An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base64 encoded Password/Username of AD accounts, the cle...
CVE-2018-11716
- EPSS 9.48%
- Published 16.07.2018 14:29:00
- Last modified 21.11.2024 03:43:53
An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled device...
CVE-2018-12999
- EPSS 9.66%
- Published 29.06.2018 12:29:00
- Last modified 21.11.2024 03:46:13
Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web server without login by sending a specially crafted request to the server with a computerName=../ subst...
CVE-2018-5340
- EPSS 7.41%
- Published 18.04.2018 08:29:00
- Last modified 21.11.2024 04:08:37
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: database access using a superuser account (specifically, an account with permission to write to the filesystem via SQL queries).
CVE-2018-5337
- EPSS 10.94%
- Published 18.04.2018 08:29:00
- Last modified 21.11.2024 04:08:36
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NAME field when modifying existing scripts.
CVE-2018-5338
- EPSS 4.34%
- Published 18.04.2018 08:29:00
- Last modified 21.11.2024 04:08:36
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanism.
CVE-2018-5339
- EPSS 2.51%
- Published 18.04.2018 08:29:00
- Last modified 21.11.2024 04:08:36
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions.
CVE-2018-5341
- EPSS 8.13%
- Published 18.04.2018 08:29:00
- Last modified 21.11.2024 04:08:37
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploading and modifying scripts.
CVE-2018-5342
- EPSS 2.17%
- Published 18.04.2018 08:29:00
- Last modified 21.11.2024 04:08:37
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: network services (Desktop Central and PostgreSQL) running with a superuser account.
CVE-2018-8722
- EPSS 1.87%
- Published 15.03.2018 04:29:00
- Last modified 21.11.2024 04:14:12
Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026.