CVE-2017-16924
- EPSS 8.89%
- Veröffentlicht 19.02.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 03:17:15
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/colle...
CVE-2015-2560
- EPSS 15.61%
- Veröffentlicht 02.08.2017 19:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet.
CVE-2017-11346
- EPSS 43.27%
- Veröffentlicht 17.07.2017 13:18:21
- Zuletzt bearbeitet 13.05.2026 00:24:29
Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos.
- EPSS 8.09%
- Veröffentlicht 15.05.2017 10:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified vectors.
CVE-2014-9331
- EPSS 4.61%
- Veröffentlicht 04.02.2015 16:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an addUser action to S...
- EPSS 19.09%
- Veröffentlicht 16.12.2014 18:59:17
- Zuletzt bearbeitet 06.05.2026 22:30:45
The NativeAppServlet in ManageEngine Desktop Central MSP before 90075 allows remote attackers to execute arbitrary code via a crafted JSON object.
CVE-2014-5005
- EPSS 77.85%
- Veröffentlicht 21.10.2014 15:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter in an LFU action to statusUpdate.
CVE-2014-5006
- EPSS 25.08%
- Veröffentlicht 21.10.2014 15:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter to mdm/mdmLogUploader.