CVE-2017-16924
- EPSS 1.73%
- Published 19.02.2018 04:29:00
- Last modified 21.11.2024 03:17:15
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/colle...
CVE-2015-2560
- EPSS 20.36%
- Published 02.08.2017 19:29:00
- Last modified 20.04.2025 01:37:25
Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet.
CVE-2017-11346
- EPSS 24.99%
- Published 17.07.2017 13:18:21
- Last modified 20.04.2025 01:37:25
Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos.
- EPSS 10.41%
- Published 15.05.2017 10:29:00
- Last modified 20.04.2025 01:37:25
Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified vectors.
CVE-2014-9331
- EPSS 2.05%
- Published 04.02.2015 16:59:01
- Last modified 12.04.2025 10:46:40
Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an addUser action to S...
- EPSS 10.22%
- Published 16.12.2014 18:59:17
- Last modified 12.04.2025 10:46:40
The NativeAppServlet in ManageEngine Desktop Central MSP before 90075 allows remote attackers to execute arbitrary code via a crafted JSON object.
CVE-2014-5005
- EPSS 85.83%
- Published 21.10.2014 15:55:06
- Last modified 12.04.2025 10:46:40
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter in an LFU action to statusUpdate.
CVE-2014-5006
- EPSS 61.87%
- Published 21.10.2014 15:55:06
- Last modified 12.04.2025 10:46:40
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter to mdm/mdmLogUploader.