Vulnerabilities > Zohocorp

DATE CVE VULNERABILITY TITLE RISK
2019-04-23 CVE-2019-11469 SQL Injection vulnerability in Zohocorp Manageengine Applications Manager
Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection.
network
low complexity
zohocorp CWE-89
critical
9.8
2019-04-22 CVE-2019-11448 SQL Injection vulnerability in Zohocorp Manageengine Applications Manager
An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0.
network
low complexity
zohocorp CWE-89
critical
9.8
2019-04-04 CVE-2019-10273 Improper Authentication vulnerability in Zohocorp Manageengine Servicedesk Plus 9.3
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users.
network
low complexity
zohocorp CWE-287
4.3
2019-03-25 CVE-2017-9376 Improper Input Validation vulnerability in Zohocorp Manageengine Servicedesk Plus
ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do.
network
low complexity
zohocorp CWE-20
6.5
2019-03-25 CVE-2017-9362 XXE vulnerability in Zohocorp Manageengine Servicedesk Plus
ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.
network
low complexity
zohocorp CWE-611
8.8
2019-03-21 CVE-2019-7425 Cross-site Scripting vulnerability in Zohocorp Manageengine Netflow Analyzer 7.0.0.2
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the task parameter.
network
low complexity
zohocorp CWE-79
6.1
2019-03-21 CVE-2019-7424 Cross-site Scripting vulnerability in Zohocorp Manageengine Netflow Analyzer 7.0.0.2
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/index.jsp" file in the view GET parameter or any of these POST parameters: autorefTime, section, snapshot, viewOpt, viewAll, view, or groupSelName.
network
low complexity
zohocorp CWE-79
6.1
2019-03-21 CVE-2019-7423 Cross-site Scripting vulnerability in Zohocorp Manageengine Netflow Analyzer 7.0.0.2
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/editProfile.jsp" file in the userName parameter.
network
low complexity
zohocorp CWE-79
6.1
2019-03-21 CVE-2019-7422 Cross-site Scripting vulnerability in Zohocorp Manageengine Netflow Analyzer 7.0.0.2
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/addMailSettings.jsp" file in the gF parameter.
network
low complexity
zohocorp CWE-79
6.1
2019-03-21 CVE-2019-7161 Use of Hard-coded Credentials vulnerability in Zohocorp Manageengine Adselfservice Plus
An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704.
network
low complexity
zohocorp CWE-798
7.5