Vulnerabilities > Zohocorp

DATE CVE VULNERABILITY TITLE RISK
2017-11-05 CVE-2017-16542 SQL Injection vulnerability in Zohocorp Manageengine Applications Manager 13.0
Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.
network
low complexity
zohocorp CWE-89
6.5
2017-09-30 CVE-2017-14582 Improper Certificate Validation vulnerability in Zohocorp Site24X7 Mobile Network Poller
The Zoho Site24x7 Mobile Network Poller application before 1.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a self-signed certificate.
network
zohocorp CWE-295
4.3
2017-09-04 CVE-2017-14123 Unrestricted Upload of File with Dangerous Type vulnerability in Zohocorp Manageengine Firewall Analyzer 12.2
Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section.
network
low complexity
zohocorp CWE-434
critical
9.0
2017-08-04 CVE-2015-9107 Cryptographic Issues vulnerability in Zohocorp Manageengine Opmanager
Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices.
network
low complexity
zohocorp CWE-310
5.0
2017-08-02 CVE-2015-2560 Permissions, Privileges, and Access Controls vulnerability in Zohocorp Manageengine Desktop Central 9.0
Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet.
network
low complexity
zohocorp CWE-264
5.0
2017-07-27 CVE-2017-11687 Cross-site Scripting vulnerability in Zohocorp Manageengine Eventlog Analyzer 11.4/11.5
Multiple Persistent cross-site scripting (XSS) vulnerabilities in Event log parsing and Display functions in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML via syslog.
network
zohocorp CWE-79
4.3
2017-07-27 CVE-2017-11686 Cross-site Scripting vulnerability in Zohocorp Manageengine Eventlog Analyzer 11.4/11.5
Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the password is represented in a cookie with a reversible encoding method.
network
zohocorp CWE-79
4.3
2017-07-27 CVE-2017-11685 Cross-site Scripting vulnerability in Zohocorp Manageengine Eventlog Analyzer 11.4/11.5
Multiple Reflective cross-site scripting (XSS) vulnerabilities in search and display of event data in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML, as demonstrated by the fName parameter.
network
zohocorp CWE-79
4.3
2017-07-17 CVE-2017-11346 Improper Input Validation vulnerability in Zohocorp Manageengine Desktop Central
Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos.
network
low complexity
zohocorp CWE-20
7.5
2017-06-27 CVE-2015-7781 Permission Issues vulnerability in Zohocorp Manageengine Firewall Analyzer 7.2/7.4/7.6
ManageEngine Firewall Analyzer before 8.0 does not restrict access permissions.
network
low complexity
zohocorp CWE-275
5.0