Vulnerabilities > Zohocorp > Manageengine Eventlog Analyzer > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-07-02 | CVE-2018-10076 | Cross-site Scripting vulnerability in Zohocorp Manageengine Eventlog Analyzer 11.12 An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. | 6.1 |
2018-07-02 | CVE-2018-10075 | Cross-site Scripting vulnerability in Zohocorp Manageengine Eventlog Analyzer 11.12 Cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer 11.12 allows remote attackers to inject arbitrary web script or HTML via the import logs feature. | 6.1 |
2018-03-15 | CVE-2018-8721 | Cross-site Scripting vulnerability in Zohocorp Manageengine Eventlog Analyzer 11.0 Zoho ManageEngine EventLog Analyzer version 11.0 build 11000 has Stored XSS related to the index2.do?url=editAlertForm&tab=alert&alert=profile URI and the Edit Alert Profile screen | 6.1 |
2018-03-13 | CVE-2018-7405 | Cross-site Scripting vulnerability in Zohocorp Manageengine Eventlog Analyzer Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 6.1 |
2017-07-27 | CVE-2017-11687 | Cross-site Scripting vulnerability in Zohocorp Manageengine Eventlog Analyzer 11.4/11.5 Multiple Persistent cross-site scripting (XSS) vulnerabilities in Event log parsing and Display functions in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML via syslog. | 6.1 |
2017-07-27 | CVE-2017-11686 | Cross-site Scripting vulnerability in Zohocorp Manageengine Eventlog Analyzer 11.4/11.5 Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the password is represented in a cookie with a reversible encoding method. | 6.1 |
2017-07-27 | CVE-2017-11685 | Cross-site Scripting vulnerability in Zohocorp Manageengine Eventlog Analyzer 11.4/11.5 Multiple Reflective cross-site scripting (XSS) vulnerabilities in search and display of event data in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML, as demonstrated by the fName parameter. | 6.1 |