- EPSS 77.48%
- Veröffentlicht 08.05.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:58:05
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attacker to bypass authentication for this server and execute all operations in the context of admin user.
CVE-2020-11531
- EPSS 13.66%
- Veröffentlicht 08.05.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:58:05
The DataEngine Xnode Server application in Zoho ManageEngine DataSecurity Plus prior to 6.0.1 does not validate the database schema name when handling a DR-SCHEMA-SYNC request. This allows an authenticated attacker to execute code in the context of t...
CVE-2018-19118
- EPSS 6.74%
- Veröffentlicht 13.12.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:57:21
Zoho ManageEngine ADAudit before 5.1 build 5120 allows remote attackers to cause a denial of service (stack-based buffer overflow) via the 'Domain Name' field when adding a new domain.
CVE-2018-10466
- EPSS 8.32%
- Veröffentlicht 29.05.2018 20:29:02
- Zuletzt bearbeitet 21.11.2024 03:41:22
Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection.