- EPSS 3.47%
- Veröffentlicht 16.08.2019 03:15:11
- Zuletzt bearbeitet 21.11.2024 04:28:03
An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM ...
- EPSS 3.27%
- Veröffentlicht 16.08.2019 03:15:11
- Zuletzt bearbeitet 21.11.2024 04:28:03
An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the se...
CVE-2017-11557
- EPSS 1.03%
- Veröffentlicht 23.05.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:08:00
An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names and usernames used in a company's network environment via a userconfiguration.do?method=editUser reque...
CVE-2017-11740
- EPSS 1.84%
- Veröffentlicht 23.05.2019 16:29:08
- Zuletzt bearbeitet 21.11.2024 03:08:24
In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse this functionality by uploading a malicious script...
CVE-2017-11739
- EPSS 1.85%
- Veröffentlicht 23.05.2019 16:29:08
- Zuletzt bearbeitet 21.11.2024 03:08:24
In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard. This widget can be a "Utility Widget" with a "Custom HTML or Text" field. Once this wi...
CVE-2017-11738
- EPSS 0.84%
- Veröffentlicht 23.05.2019 16:29:08
- Zuletzt bearbeitet 21.11.2024 03:08:24
In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack.
- EPSS 4.67%
- Veröffentlicht 23.04.2019 04:29:01
- Zuletzt bearbeitet 21.11.2024 04:21:08
Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious file via the "Execute Program...
- EPSS 19.38%
- Veröffentlicht 22.04.2019 11:29:06
- Zuletzt bearbeitet 21.11.2024 04:21:05
An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For example, the attacker can subseque...
CVE-2018-16364
- EPSS 2.36%
- Veröffentlicht 26.09.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 03:52:36
A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload on an SMB share.
CVE-2018-15169
- EPSS 0.42%
- Veröffentlicht 08.08.2018 00:29:01
- Zuletzt bearbeitet 21.11.2024 03:50:27
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to inject arbitrary web script or HTML via the /deleteMO.do method parameter.