Filtered by vendor Zohocorp Subscriptions
Total 497 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2018-10803 1 Zohocorp 1 Manageengine Netflow Analyzer 2024-11-21 N/A
Cross-site scripting (XSS) vulnerability in the add credentials functionality in Zoho ManageEngine NetFlow Analyzer v12.3 before 12.3.125 (build 123125) allows remote attackers to inject arbitrary web script or HTML via a crafted description value. This can be exploited through CSRF.
CVE-2018-10466 1 Zohocorp 1 Manageengine Adaudit Plus 2024-11-21 N/A
Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection.
CVE-2018-10076 1 Zohocorp 1 Manageengine Eventlog Analyzer 2024-11-21 N/A
An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. A Cross-Site Scripting vulnerability allows a remote attacker to inject arbitrary web script or HTML via the search functionality (the search box of the Dashboard).
CVE-2018-10075 1 Zohocorp 1 Manageengine Eventlog Analyzer 2024-11-21 N/A
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer 11.12 allows remote attackers to inject arbitrary web script or HTML via the import logs feature.
CVE-2017-9376 1 Zohocorp 1 Manageengine Servicedesk Plus 2024-11-21 N/A
ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do.
CVE-2017-9362 1 Zohocorp 1 Manageengine Servicedesk Plus 2024-11-21 N/A
ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.
CVE-2017-7213 1 Zohocorp 1 Manageengine Desktop Central 2024-11-21 N/A
Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified vectors.
CVE-2017-17698 1 Zohocorp 1 Manageengine Password Manager Pro 2024-11-21 N/A
Zoho ManageEngine Password Manager Pro 9 before 9.4 (9400) has reflected XSS in SearchResult.ec and BulkAccessControlView.ec.
CVE-2017-17552 1 Zohocorp 1 Manageengine Admanager Plus 2024-11-21 N/A
/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted.
CVE-2017-16924 1 Zohocorp 1 Manageengine Desktop Central 2024-11-21 N/A
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/collections/##/usermgmt.xml URL, as demonstrated by passwords and Wi-Fi keys. This is fixed in build 100157.
CVE-2017-16851 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 N/A
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter.
CVE-2017-16850 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 N/A
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfiles action.
CVE-2017-16849 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 N/A
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoard forpage parameter.
CVE-2017-16848 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 N/A
Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter.
CVE-2017-16847 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 N/A
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a showPlasmaView action.
CVE-2017-16846 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 N/A
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter.
CVE-2017-16543 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 N/A
Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.
CVE-2017-16542 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 N/A
Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.
CVE-2017-14582 1 Zohocorp 1 Site24x7 Mobile Network Poller 2024-11-21 N/A
The Zoho Site24x7 Mobile Network Poller application before 1.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a self-signed certificate.
CVE-2017-14123 1 Zohocorp 1 Manageengine Firewall Analyzer 2024-11-21 8.8 High
Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section. Any user can upload files with any extensions. By uploading a PHP file to the server, an attacker can cause it to execute in the server context, as demonstrated by /itplus/FileStorage/302/shell.jsp.