Skip to main content

Vendor archive

zohocorp CVEs

Beta · best-effort

550 CVEs tagged to vendor zohocorp143 Critical, 196 High, 201 Medium, 10 Low, 0 Unrated.

CVE-2018-10076

Published Jul 2, 2018

An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. A Cross-Site Scripting vulnerability allows a remote attacker to inject arbitrary web script or HTML via the…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10075

Published Jul 2, 2018

Cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer 11.12 allows remote attackers to inject arbitrary web script or HTML via the import logs feature.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-12999

Published Jun 29, 2018

Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web server without login by sending…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12996

Published Jun 29, 2018

A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote attackers to inject arbitrary web script or HT…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11808

Published Jun 6, 2018

Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Version 13 before build 13740 allows an attacker to delete any file and read certain…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-7248

Published May 11, 2018

An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the u…

CVSS 5.3 · Medium
Buzz score
4.6
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2018-5342

Published Apr 18, 2018

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: network services (Desktop Central and PostgreSQL) running with a superuser account.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5341

Published Apr 18, 2018

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploading and modifying scripts.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-5340

Published Apr 18, 2018

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: database access using a superuser account (specifically, an account with permission to write to…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5337

Published Apr 18, 2018

An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NAME field when modifying existing scripts.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-9163

Published Apr 2, 2018

A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) allows remote authenticated users (with Add New Technician per…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5799

Published Mar 30, 2018

In Zoho ManageEngine ServiceDesk Plus before 9403, an XSS issue allows an attacker to run arbitrary JavaScript via a /api/request/?OPERATION_NAME= URI, aka SD-69139.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-8721

Published Mar 15, 2018

Zoho ManageEngine EventLog Analyzer version 11.0 build 11000 has Stored XSS related to the index2.do?url=editAlertForm&tab=alert&alert=profile URI and the Edit Alert Profile screen

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-7405

Published Mar 13, 2018

Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-7890

Published Mar 8, 2018

A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredential.do endpoint takes multiple…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-16924

Published Feb 19, 2018

Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 451-475 of 550 CVEsPage 19 of 22