Vulnerabilities > Zohocorp

DATE CVE VULNERABILITY TITLE RISK
2018-04-18 CVE-2018-5341 Improper Input Validation vulnerability in Zohocorp Manageengine Desktop Central 10.0.124/10.0.184
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploading and modifying scripts.
network
low complexity
zohocorp CWE-20
critical
9.8
2018-04-18 CVE-2018-5340 Unspecified vulnerability in Zohocorp Manageengine Desktop Central 10.0.124/10.0.184
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: database access using a superuser account (specifically, an account with permission to write to the filesystem via SQL queries).
network
low complexity
zohocorp
7.2
2018-04-18 CVE-2018-5339 Missing Authentication for Critical Function vulnerability in Zohocorp Manageengine Desktop Central 10.0.124/10.0.184
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions.
network
low complexity
zohocorp CWE-306
critical
9.8
2018-04-18 CVE-2018-5338 Missing Authentication for Critical Function vulnerability in Zohocorp Manageengine Desktop Central 10.0.124/10.0.184
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanism.
network
low complexity
zohocorp CWE-306
critical
9.8
2018-04-18 CVE-2018-5337 Path Traversal vulnerability in Zohocorp Manageengine Desktop Central 10.0.124/10.0.184
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NAME field when modifying existing scripts.
network
low complexity
zohocorp CWE-22
critical
9.8
2018-04-02 CVE-2018-9163 Cross-site Scripting vulnerability in Zohocorp Manageengine Recovery Manager Plus
A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) allows remote authenticated users (with Add New Technician permissions) to inject arbitrary web script or HTML via the loginName field to technicianAction.do.
network
low complexity
zohocorp CWE-79
5.4
2018-03-30 CVE-2018-5799 Cross-site Scripting vulnerability in Zohocorp Manageengine Servicedesk Plus
In Zoho ManageEngine ServiceDesk Plus before 9403, an XSS issue allows an attacker to run arbitrary JavaScript via a /api/request/?OPERATION_NAME= URI, aka SD-69139.
network
low complexity
zohocorp CWE-79
6.1
2018-03-15 CVE-2018-8722 Cross-site Scripting vulnerability in Zohocorp Manageengine Desktop Central 9.1.0
Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026.
network
low complexity
zohocorp CWE-79
6.1
2018-03-15 CVE-2018-8721 Cross-site Scripting vulnerability in Zohocorp Manageengine Eventlog Analyzer 11.0
Zoho ManageEngine EventLog Analyzer version 11.0 build 11000 has Stored XSS related to the index2.do?url=editAlertForm&tab=alert&alert=profile URI and the Edit Alert Profile screen
network
low complexity
zohocorp CWE-79
6.1
2018-03-13 CVE-2018-7405 Cross-site Scripting vulnerability in Zohocorp Manageengine Eventlog Analyzer
Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
zohocorp CWE-79
6.1