Vulnerabilities > Zohocorp > Manageengine Desktop Central

DATE CVE VULNERABILITY TITLE RISK
2018-02-19 CVE-2017-16924 Use of Insufficiently Random Values vulnerability in Zohocorp Manageengine Desktop Central 10.0.137
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/collections/##/usermgmt.xml URL, as demonstrated by passwords and Wi-Fi keys.
network
low complexity
zohocorp CWE-330
critical
9.8
2017-08-02 CVE-2015-2560 Permissions, Privileges, and Access Controls vulnerability in Zohocorp Manageengine Desktop Central 9.0
Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet.
network
low complexity
zohocorp CWE-264
critical
9.8
2017-07-17 CVE-2017-11346 Improper Input Validation vulnerability in Zohocorp Manageengine Desktop Central
Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos.
network
low complexity
zohocorp CWE-20
critical
9.8
2017-05-15 CVE-2017-7213 Improper Input Validation vulnerability in Zohocorp Manageengine Desktop Central
Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified vectors.
network
low complexity
zohocorp CWE-20
critical
10.0