Zohocorp

Manageengine Desktop Central

48 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 9.61%
  • Veröffentlicht 16.07.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:43:53

An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base64 encoded Password/Username of AD accounts, the cle...

Exploit
  • EPSS 9.48%
  • Veröffentlicht 16.07.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:43:53

An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled device...

Exploit
  • EPSS 9.66%
  • Veröffentlicht 29.06.2018 12:29:00
  • Zuletzt bearbeitet 21.11.2024 03:46:13

Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web server without login by sending a specially crafted request to the server with a computerName=../ subst...

Exploit
  • EPSS 7.06%
  • Veröffentlicht 18.04.2018 08:29:00
  • Zuletzt bearbeitet 21.11.2024 04:08:37

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: database access using a superuser account (specifically, an account with permission to write to the filesystem via SQL queries).

Exploit
  • EPSS 10.45%
  • Veröffentlicht 18.04.2018 08:29:00
  • Zuletzt bearbeitet 21.11.2024 04:08:36

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NAME field when modifying existing scripts.

Exploit
  • EPSS 4.13%
  • Veröffentlicht 18.04.2018 08:29:00
  • Zuletzt bearbeitet 21.11.2024 04:08:36

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanism.

Exploit
  • EPSS 2.38%
  • Veröffentlicht 18.04.2018 08:29:00
  • Zuletzt bearbeitet 21.11.2024 04:08:36

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions.

Exploit
  • EPSS 7.75%
  • Veröffentlicht 18.04.2018 08:29:00
  • Zuletzt bearbeitet 21.11.2024 04:08:37

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploading and modifying scripts.

Exploit
  • EPSS 2.07%
  • Veröffentlicht 18.04.2018 08:29:00
  • Zuletzt bearbeitet 21.11.2024 04:08:37

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: network services (Desktop Central and PostgreSQL) running with a superuser account.

  • EPSS 1.87%
  • Veröffentlicht 15.03.2018 04:29:00
  • Zuletzt bearbeitet 21.11.2024 04:14:12

Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026.