Vulnerabilities > Zohocorp

DATE CVE VULNERABILITY TITLE RISK
2017-09-30 CVE-2017-14582 Improper Certificate Validation vulnerability in Zohocorp Site24X7 Mobile Network Poller 1.1.4
The Zoho Site24x7 Mobile Network Poller application before 1.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a self-signed certificate.
network
high complexity
zohocorp CWE-295
5.9
2017-09-04 CVE-2017-14123 Unrestricted Upload of File with Dangerous Type vulnerability in Zohocorp Manageengine Firewall Analyzer 12.2
Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section.
network
low complexity
zohocorp CWE-434
8.8
2017-08-04 CVE-2015-9107 Cryptographic Issues vulnerability in Zohocorp Manageengine Opmanager
Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices.
network
low complexity
zohocorp CWE-310
critical
9.8
2017-08-02 CVE-2015-2560 Permissions, Privileges, and Access Controls vulnerability in Zohocorp Manageengine Desktop Central 9.0
Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet.
network
low complexity
zohocorp CWE-264
critical
9.8
2017-07-27 CVE-2017-11687 Cross-site Scripting vulnerability in Zohocorp Manageengine Eventlog Analyzer 11.4/11.5
Multiple Persistent cross-site scripting (XSS) vulnerabilities in Event log parsing and Display functions in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML via syslog.
network
low complexity
zohocorp CWE-79
6.1
2017-07-27 CVE-2017-11686 Cross-site Scripting vulnerability in Zohocorp Manageengine Eventlog Analyzer 11.4/11.5
Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the password is represented in a cookie with a reversible encoding method.
network
low complexity
zohocorp CWE-79
6.1
2017-07-27 CVE-2017-11685 Cross-site Scripting vulnerability in Zohocorp Manageengine Eventlog Analyzer 11.4/11.5
Multiple Reflective cross-site scripting (XSS) vulnerabilities in search and display of event data in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML, as demonstrated by the fName parameter.
network
low complexity
zohocorp CWE-79
6.1
2017-07-17 CVE-2017-11346 Improper Input Validation vulnerability in Zohocorp Manageengine Desktop Central
Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos.
network
low complexity
zohocorp CWE-20
critical
9.8
2017-06-27 CVE-2015-7781 Permission Issues vulnerability in Zohocorp Manageengine Firewall Analyzer 7.2/7.4/7.6
ManageEngine Firewall Analyzer before 8.0 does not restrict access permissions.
network
low complexity
zohocorp CWE-275
7.5
2017-06-27 CVE-2015-7780 Path Traversal vulnerability in Zohocorp Manageengine Firewall Analyzer 7.2/7.4/7.6
Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0.
network
low complexity
zohocorp CWE-22
6.5