Zohocorp

Manageengine Desktop Central

48 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 9.61%
  • Published 16.07.2018 14:29:00
  • Last modified 21.11.2024 03:43:53

An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base64 encoded Password/Username of AD accounts, the cle...

Exploit
  • EPSS 9.48%
  • Published 16.07.2018 14:29:00
  • Last modified 21.11.2024 03:43:53

An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled device...

Exploit
  • EPSS 9.66%
  • Published 29.06.2018 12:29:00
  • Last modified 21.11.2024 03:46:13

Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web server without login by sending a specially crafted request to the server with a computerName=../ subst...

Exploit
  • EPSS 7.41%
  • Published 18.04.2018 08:29:00
  • Last modified 21.11.2024 04:08:37

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: database access using a superuser account (specifically, an account with permission to write to the filesystem via SQL queries).

Exploit
  • EPSS 10.94%
  • Published 18.04.2018 08:29:00
  • Last modified 21.11.2024 04:08:36

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NAME field when modifying existing scripts.

Exploit
  • EPSS 4.34%
  • Published 18.04.2018 08:29:00
  • Last modified 21.11.2024 04:08:36

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanism.

Exploit
  • EPSS 2.51%
  • Published 18.04.2018 08:29:00
  • Last modified 21.11.2024 04:08:36

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions.

Exploit
  • EPSS 8.13%
  • Published 18.04.2018 08:29:00
  • Last modified 21.11.2024 04:08:37

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploading and modifying scripts.

Exploit
  • EPSS 2.17%
  • Published 18.04.2018 08:29:00
  • Last modified 21.11.2024 04:08:37

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: network services (Desktop Central and PostgreSQL) running with a superuser account.

  • EPSS 1.87%
  • Published 15.03.2018 04:29:00
  • Last modified 21.11.2024 04:14:12

Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026.