Vulnerabilities > Zohocorp

DATE CVE VULNERABILITY TITLE RISK
2020-01-31 CVE-2020-8422 Unspecified vulnerability in Zohocorp Manageengine Remote Access Plus
An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 10.0.450.
network
low complexity
zohocorp
4.3
2020-01-27 CVE-2013-7390 Unrestricted Upload of File with Dangerous Type vulnerability in Zohocorp Manageengine Desktop Central 7.0.0/7.0.1/8.0.0
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the webroot.
network
low complexity
zohocorp CWE-434
critical
9.8
2020-01-23 CVE-2020-6843 Cross-site Scripting vulnerability in Zohocorp Manageengine Servicedesk Plus
Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007 allows XSS.
network
low complexity
zohocorp CWE-79
4.8
2020-01-17 CVE-2014-5007 Path Traversal vulnerability in Zohocorp products
Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90055 allows remote attackers to write to and execute arbitrary files as SYSTEM via a ..
network
low complexity
zohocorp CWE-22
critical
9.8
2020-01-13 CVE-2014-6039 Insufficiently Protected Credentials vulnerability in Zohocorp Manageengine Eventlog Analyzer
ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability.
network
low complexity
zohocorp CWE-522
7.5
2020-01-13 CVE-2014-6038 Information Exposure vulnerability in Zohocorp Manageengine Eventlog Analyzer
Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability.
network
low complexity
zohocorp CWE-200
7.5
2020-01-10 CVE-2019-19475 Incorrect Default Permissions vulnerability in Zohocorp Manageengine Applications Manager 14.3
An issue was discovered in ManageEngine Applications Manager 14 with Build 14360.
network
low complexity
zohocorp CWE-276
8.8
2019-12-31 CVE-2019-7162 Unspecified vulnerability in Zohocorp Manageengine Adselfservice Plus 5.6
An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.6 Build 5607.
network
low complexity
zohocorp
critical
9.1
2019-12-18 CVE-2019-18781 Open Redirect vulnerability in Zohocorp Manageengine Adselfservice Plus
An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent to a specified external site.
network
low complexity
zohocorp CWE-601
6.1
2019-12-13 CVE-2019-19774 Unspecified vulnerability in Zohocorp Manageengine Eventlog Analyzer
An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110.
network
low complexity
zohocorp
8.8