Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
9.8
CVE-2017-16846
- EPSS 16.64%
- Veröffentlicht 16.11.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter.
8.8
CVE-2017-16542
- EPSS 5.49%
- Veröffentlicht 05.11.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.
9.8
CVE-2017-16543
- EPSS 5.56%
- Veröffentlicht 05.11.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.