Перейти к содержимому
Noroxi

Записи ManageEngine

46 опубликованных записей вендора manageengine.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
6 · 13 %
Pre-auth RCE
7
С записью об исправлении
2,2 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

46 записей
  • CVE-2015-8249
    61На этой неделе

    The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary fil

    КритическаяCVSS 9,8Готовый эксплойтEPSS 74 %

    manageengine · desktop central27 сент. 2017 г.

  • CVE-2014-5301
    59В плане

    Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 78 %

    manageengine · servicedesk plus28 авг. 2017 г.

  • CVE-2017-11512
    54В плане

    The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the nam

    ВысокаяCVSS 7,5Proof of conceptEPSS 80 %

    manageengine · servicedesk8 нояб. 2017 г.

  • CVE-2014-3996
    42В плане

    SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Pro

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 38 %

    manageengine · it3605 дек. 2014 г.

  • CVE-2007-2429
    42В плане

    ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command

    КритическаяCVSS 10,0Proof of conceptEPSS 8 %

    manageengine · passwordmanager pro1 мая 2007 г.

  • CVE-2014-9373
    42В плане

    Directory traversal vulnerability in the CollectorConfInfoServlet servlet in ManageEngine NetFlow Analyzer allows remote attackers to execut

    КритическаяCVSS 10,0Эксплойта нетEPSS 6 %

    manageengine · netflow analyzer16 дек. 2014 г.

  • CVE-2016-9488
    40В плане

    ManageEngine Applications Manager versions 12 and 13 suffer from remote SQL injection vulnerabilities

    КритическаяCVSS 9,8Proof of conceptEPSS 5 %

    manageengine · applications manager5 июн. 2018 г.

  • CVE-2021-28960
    40В плане

    Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input comman

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    manageengine · desktop central21 сент. 2021 г.

  • CVE-2014-5302
    38Наблюдать

    Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9

    ВысокаяCVSS 8,8Эксплойта нетEPSS 11 %

    manageengine · servicedesk plus28 авг. 2017 г.

  • CVE-2014-5377
    37Наблюдать

    ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via

    СредняяCVSS 5,0Готовый эксплойтEPSS 57 %

    manageengine · device expert4 сент. 2014 г.

  • CVE-2014-8499
    37Наблюдать

    Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) e

    СредняяCVSS 6,5Готовый эксплойтEPSS 36 %

    manageengine · password manager pro17 нояб. 2014 г.

  • CVE-2011-2757
    32Наблюдать

    Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read

    СредняяCVSS 5,0Готовый эксплойтEPSS 39 %

    manageengine · servicedesk plus17 июл. 2011 г.

  • CVE-2014-8678
    32Наблюдать

    The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via a crafted filename,

    ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %

    manageengine · oputils25 нояб. 2014 г.

  • CVE-2017-11511
    31Наблюдать

    The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the fil

    ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

    manageengine · servicedesk8 нояб. 2017 г.

  • CVE-2010-4840
    31Наблюдать

    Multiple buffer overflows in the Syslog server in ManageEngine EventLog Analyzer 6.1 allow remote attackers to cause a denial of service (Sy

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    manageengine · eventlog analyzer27 сент. 2011 г.

  • CVE-2012-1063
    30Наблюдать

    Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL com

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    manageengine · applications manager13 февр. 2012 г.

  • CVE-2010-1044
    30Наблюдать

    SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL commands via the isHttp

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    manageengine · oputils22 мар. 2010 г.

  • CVE-2011-2755
    29Наблюдать

    Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to read

    СредняяCVSS 5,0Proof of conceptEPSS 31 %

    manageengine · servicedesk plus17 июл. 2011 г.

  • CVE-2014-9372
    26Наблюдать

    Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remot

    СредняяCVSS 6,4Эксплойта нетEPSS 2 %

    manageengine · password manager pro16 дек. 2014 г.

  • CVE-2018-15608
    25Наблюдать

    Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.

    СредняяCVSS 6,1Proof of conceptEPSS 2 %

    manageengine · admanager plus28 авг. 2018 г.

  • CVE-2016-9490
    25Наблюдать

    ManageEngine Applications Manager versions 12 and 13 suffer from a Reflected Cross-Site Scripting vulnerability

    СредняяCVSS 6,1Эксплойта нетEPSS 2 %

    manageengine · applications manager5 июн. 2018 г.

  • CVE-2008-0476
    25Наблюдать

    ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows

    СредняяCVSS 6,4Эксплойта нетEPSS 1 %

    manageengine · applications manager29 янв. 2008 г.

  • CVE-2008-1299
    24Наблюдать

    Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Windows allows remote at

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    manageengine · servicedesk plus12 мар. 2008 г.

  • CVE-2020-19554
    24Наблюдать

    Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174 when the API key contains an XML-based XSS payload.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    manageengine · opmanager21 сент. 2021 г.

  • CVE-2011-2756
    21Наблюдать

    FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to re

    СредняяCVSS 5,0Эксплойта нетEPSS 2 %

    manageengine · servicedesk plus17 июл. 2011 г.