Skip to main content

Vendor archive

zohocorp CVEs

Beta · best-effort

550 CVEs tagged to vendor zohocorp143 Critical, 196 High, 201 Medium, 10 Low, 0 Unrated.

CVE-2017-17552

Published Feb 7, 2018

/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protecti…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-7862

Published Jan 4, 2018

The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUs…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-16543

Published Nov 5, 2017

Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-14582

Published Sep 30, 2017

The Zoho Site24x7 Mobile Network Poller application before 1.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14123

Published Sep 4, 2017

Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section. Any user can upload files with any extensions. By uploading a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-9107

Published Aug 4, 2017

Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The implemented algorithm doesn't us…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-2560

Published Aug 2, 2017

Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DC…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-11687

Published Jul 27, 2017

Multiple Persistent cross-site scripting (XSS) vulnerabilities in Event log parsing and Display functions in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attack…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11686

Published Jul 27, 2017

Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the ne…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11685

Published Jul 27, 2017

Multiple Reflective cross-site scripting (XSS) vulnerabilities in search and display of event data in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11346

Published Jul 17, 2017

Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7213

Published May 15, 2017

Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-4890

Published Apr 14, 2017

ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive password information by lever…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4889

Published Apr 14, 2017

ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict access to unknown functions.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 476-500 of 550 CVEsPage 20 of 22