Zohocorp

Manageengine Applications Manager

56 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 3.47%
  • Veröffentlicht 16.08.2019 03:15:11
  • Zuletzt bearbeitet 21.11.2024 04:28:03

An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM ...

Exploit
  • EPSS 3.27%
  • Veröffentlicht 16.08.2019 03:15:11
  • Zuletzt bearbeitet 21.11.2024 04:28:03

An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the se...

Exploit
  • EPSS 1.03%
  • Veröffentlicht 23.05.2019 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:08:00

An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names and usernames used in a company's network environment via a userconfiguration.do?method=editUser reque...

Exploit
  • EPSS 1.84%
  • Veröffentlicht 23.05.2019 16:29:08
  • Zuletzt bearbeitet 21.11.2024 03:08:24

In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse this functionality by uploading a malicious script...

Exploit
  • EPSS 1.85%
  • Veröffentlicht 23.05.2019 16:29:08
  • Zuletzt bearbeitet 21.11.2024 03:08:24

In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard. This widget can be a "Utility Widget" with a "Custom HTML or Text" field. Once this wi...

Exploit
  • EPSS 0.84%
  • Veröffentlicht 23.05.2019 16:29:08
  • Zuletzt bearbeitet 21.11.2024 03:08:24

In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack.

Exploit
  • EPSS 4.67%
  • Veröffentlicht 23.04.2019 04:29:01
  • Zuletzt bearbeitet 21.11.2024 04:21:08

Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious file via the "Execute Program...

Exploit
  • EPSS 19.38%
  • Veröffentlicht 22.04.2019 11:29:06
  • Zuletzt bearbeitet 21.11.2024 04:21:05

An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For example, the attacker can subseque...

Exploit
  • EPSS 2.36%
  • Veröffentlicht 26.09.2018 21:29:01
  • Zuletzt bearbeitet 21.11.2024 03:52:36

A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload on an SMB share.

Exploit
  • EPSS 0.42%
  • Veröffentlicht 08.08.2018 00:29:01
  • Zuletzt bearbeitet 21.11.2024 03:50:27

A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to inject arbitrary web script or HTML via the /deleteMO.do method parameter.