Zohocorp

Manageengine Desktop Central

48 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.73%
  • Published 19.02.2018 04:29:00
  • Last modified 21.11.2024 03:17:15

Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/colle...

Exploit
  • EPSS 20.36%
  • Published 02.08.2017 19:29:00
  • Last modified 20.04.2025 01:37:25

Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet.

  • EPSS 24.99%
  • Published 17.07.2017 13:18:21
  • Last modified 20.04.2025 01:37:25

Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos.

  • EPSS 10.41%
  • Published 15.05.2017 10:29:00
  • Last modified 20.04.2025 01:37:25

Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified vectors.

Exploit
  • EPSS 2.05%
  • Published 04.02.2015 16:59:01
  • Last modified 12.04.2025 10:46:40

Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an addUser action to S...

  • EPSS 10.22%
  • Published 16.12.2014 18:59:17
  • Last modified 12.04.2025 10:46:40

The NativeAppServlet in ManageEngine Desktop Central MSP before 90075 allows remote attackers to execute arbitrary code via a crafted JSON object.

Exploit
  • EPSS 85.83%
  • Published 21.10.2014 15:55:06
  • Last modified 12.04.2025 10:46:40

Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter in an LFU action to statusUpdate.

Exploit
  • EPSS 61.87%
  • Published 21.10.2014 15:55:06
  • Last modified 12.04.2025 10:46:40

Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter to mdm/mdmLogUploader.