Vulnerabilities > Zohocorp > Manageengine Applications Manager > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-05-23 CVE-2017-11557 Information Exposure vulnerability in Zohocorp Manageengine Applications Manager 12.3
An issue was discovered in ZOHO ManageEngine Applications Manager 12.3.
network
low complexity
zohocorp CWE-200
5.3
2019-05-23 CVE-2017-11739 Cross-site Scripting vulnerability in Zohocorp Manageengine Applications Manager 13.1
In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard.
network
low complexity
zohocorp CWE-79
6.1
2018-08-08 CVE-2018-15169 Cross-site Scripting vulnerability in Zohocorp Manageengine Applications Manager
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to inject arbitrary web script or HTML via the /deleteMO.do method parameter.
network
low complexity
zohocorp CWE-79
6.1
2018-07-13 CVE-2016-9491 Information Exposure vulnerability in Zohocorp Manageengine Applications Manager 12.0/13.0
ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem and read the system files, including Applications Manager configuration, stored private keys, etc.
network
low complexity
zohocorp CWE-200
4.9
2018-06-29 CVE-2018-12996 Cross-site Scripting vulnerability in Zohocorp Manageengine Applications Manager
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote attackers to inject arbitrary web script or HTML via the parameter 'method' to GraphicalView.do.
network
low complexity
zohocorp CWE-79
6.1