ManageEngine kayıtları
manageengine üreticisine ait 46 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 6 · %13
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %2,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')21
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')8
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-287 Improper Authentication2
- CWE-310 Cryptographic Issues1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
46 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
61Bu hafta | CVE-2015-8249Silahlaştırılmış | The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary filmanageengine · desktop central · CWE-434 | Kritik9,8 | — | %73,6 | 27 Eyl 2017 |
59Planlayın | CVE-2014-5301Silahlaştırılmış | Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to manageengine · servicedesk plus · CWE-22 | Yüksek8,8 | — | %78,4 | 28 Ağu 2017 |
54Planlayın | CVE-2017-11512Kavram kanıtı | The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the nammanageengine · servicedesk · CWE-22 | Yüksek7,5 | — | %79,6 | 8 Kas 2017 |
42Planlayın | CVE-2014-3996Silahlaştırılmış | SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Promanageengine · it360 · CWE-89 | Yüksek7,5 | — | %38,4 | 5 Ara 2014 |
42Planlayın | CVE-2007-2429Kavram kanıtı | ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command manageengine · passwordmanager pro | Kritik10,0 | — | %8,0 | 1 May 2007 |
42Planlayın | CVE-2014-9373İstismar yok | Directory traversal vulnerability in the CollectorConfInfoServlet servlet in ManageEngine NetFlow Analyzer allows remote attackers to executmanageengine · netflow analyzer · CWE-22 | Kritik10,0 | — | %6,3 | 16 Ara 2014 |
40Planlayın | CVE-2016-9488Kavram kanıtı | ManageEngine Applications Manager versions 12 and 13 suffer from remote SQL injection vulnerabilitiesmanageengine · applications manager · CWE-89 | Kritik9,8 | — | %4,7 | 5 Haz 2018 |
40Planlayın | CVE-2021-28960İstismar yok | Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input commanmanageengine · desktop central · CWE-77 | Kritik9,8 | — | %2,0 | 21 Eyl 2021 |
38İzleyin | CVE-2014-5302İstismar yok | Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9manageengine · servicedesk plus · CWE-22 | Yüksek8,8 | — | %10,7 | 28 Ağu 2017 |
37İzleyin | CVE-2014-5377Silahlaştırılmış | ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials viamanageengine · device expert · CWE-200 | Orta5,0 | — | %57,5 | 4 Eyl 2014 |
37İzleyin | CVE-2014-8499Silahlaştırılmış | Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) emanageengine · password manager pro · CWE-89 | Orta6,5 | — | %36,4 | 17 Kas 2014 |
32İzleyin | CVE-2011-2757Silahlaştırılmış | Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read manageengine · servicedesk plus · CWE-22 | Orta5,0 | — | %39,4 | 17 Tem 2011 |
32İzleyin | CVE-2014-8678İstismar yok | The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via a crafted filename,manageengine · oputils · CWE-200 | Yüksek7,8 | — | %2,3 | 25 Kas 2014 |
31İzleyin | CVE-2017-11511İstismar yok | The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filmanageengine · servicedesk · CWE-22 | Yüksek7,5 | — | %3,6 | 8 Kas 2017 |
31İzleyin | CVE-2010-4840İstismar yok | Multiple buffer overflows in the Syslog server in ManageEngine EventLog Analyzer 6.1 allow remote attackers to cause a denial of service (Symanageengine · eventlog analyzer · CWE-119 | Yüksek7,5 | — | %2,2 | 27 Eyl 2011 |
30İzleyin | CVE-2012-1063İstismar yok | Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL commanageengine · applications manager · CWE-89 | Yüksek7,5 | — | %1,2 | 13 Şub 2012 |
30İzleyin | CVE-2010-1044Kavram kanıtı | SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL commands via the isHttpmanageengine · oputils · CWE-89 | Yüksek7,5 | — | %1,0 | 22 Mar 2010 |
29İzleyin | CVE-2011-2755Kavram kanıtı | Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to readmanageengine · servicedesk plus · CWE-22 | Orta5,0 | — | %30,9 | 17 Tem 2011 |
26İzleyin | CVE-2014-9372İstismar yok | Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remotmanageengine · password manager pro · CWE-22 | Orta6,4 | — | %2,4 | 16 Ara 2014 |
25İzleyin | CVE-2018-15608Kavram kanıtı | Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.manageengine · admanager plus · CWE-79 | Orta6,1 | — | %2,5 | 28 Ağu 2018 |
25İzleyin | CVE-2016-9490İstismar yok | ManageEngine Applications Manager versions 12 and 13 suffer from a Reflected Cross-Site Scripting vulnerabilitymanageengine · applications manager · CWE-79 | Orta6,1 | — | %1,7 | 5 Haz 2018 |
25İzleyin | CVE-2008-0476İstismar yok | ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows manageengine · applications manager · CWE-287 | Orta6,4 | — | %1,2 | 29 Oca 2008 |
24İzleyin | CVE-2008-1299İstismar yok | Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Windows allows remote atmanageengine · servicedesk plus · CWE-79 | Orta6,1 | — | %0,8 | 12 Mar 2008 |
24İzleyin | CVE-2020-19554İstismar yok | Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174 when the API key contains an XML-based XSS payload.manageengine · opmanager · CWE-79 | Orta6,1 | — | %0,6 | 21 Eyl 2021 |
21İzleyin | CVE-2011-2756İstismar yok | FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to remanageengine · servicedesk plus · CWE-287 | Orta5,0 | — | %2,0 | 17 Tem 2011 |
- CVE-2015-824961Bu hafta
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary fil
KritikCVSS 9,8SilahlaştırılmışEPSS %74manageengine · desktop central27 Eyl 2017
- CVE-2014-530159Planlayın
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to
YüksekCVSS 8,8SilahlaştırılmışEPSS %78manageengine · servicedesk plus28 Ağu 2017
- CVE-2017-1151254Planlayın
The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the nam
YüksekCVSS 7,5Kavram kanıtıEPSS %80manageengine · servicedesk8 Kas 2017
- CVE-2014-399642Planlayın
SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Pro
YüksekCVSS 7,5SilahlaştırılmışEPSS %38manageengine · it3605 Ara 2014
- CVE-2007-242942Planlayın
ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command
KritikCVSS 10,0Kavram kanıtıEPSS %8manageengine · passwordmanager pro1 May 2007
- CVE-2014-937342Planlayın
Directory traversal vulnerability in the CollectorConfInfoServlet servlet in ManageEngine NetFlow Analyzer allows remote attackers to execut
KritikCVSS 10,0İstismar yokEPSS %6manageengine · netflow analyzer16 Ara 2014
- CVE-2016-948840Planlayın
ManageEngine Applications Manager versions 12 and 13 suffer from remote SQL injection vulnerabilities
KritikCVSS 9,8Kavram kanıtıEPSS %5manageengine · applications manager5 Haz 2018
- CVE-2021-2896040Planlayın
Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input comman
KritikCVSS 9,8İstismar yokEPSS %2manageengine · desktop central21 Eyl 2021
- CVE-2014-530238İzleyin
Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9
YüksekCVSS 8,8İstismar yokEPSS %11manageengine · servicedesk plus28 Ağu 2017
- CVE-2014-537737İzleyin
ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via
OrtaCVSS 5,0SilahlaştırılmışEPSS %57manageengine · device expert4 Eyl 2014
- CVE-2014-849937İzleyin
Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) e
OrtaCVSS 6,5SilahlaştırılmışEPSS %36manageengine · password manager pro17 Kas 2014
- CVE-2011-275732İzleyin
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read
OrtaCVSS 5,0SilahlaştırılmışEPSS %39manageengine · servicedesk plus17 Tem 2011
- CVE-2014-867832İzleyin
The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via a crafted filename,
YüksekCVSS 7,8İstismar yokEPSS %2manageengine · oputils25 Kas 2014
- CVE-2017-1151131İzleyin
The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the fil
YüksekCVSS 7,5İstismar yokEPSS %4manageengine · servicedesk8 Kas 2017
- CVE-2010-484031İzleyin
Multiple buffer overflows in the Syslog server in ManageEngine EventLog Analyzer 6.1 allow remote attackers to cause a denial of service (Sy
YüksekCVSS 7,5İstismar yokEPSS %2manageengine · eventlog analyzer27 Eyl 2011
- CVE-2012-106330İzleyin
Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL com
YüksekCVSS 7,5İstismar yokEPSS %1manageengine · applications manager13 Şub 2012
- CVE-2010-104430İzleyin
SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL commands via the isHttp
YüksekCVSS 7,5Kavram kanıtıEPSS %1manageengine · oputils22 Mar 2010
- CVE-2011-275529İzleyin
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to read
OrtaCVSS 5,0Kavram kanıtıEPSS %31manageengine · servicedesk plus17 Tem 2011
- CVE-2014-937226İzleyin
Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remot
OrtaCVSS 6,4İstismar yokEPSS %2manageengine · password manager pro16 Ara 2014
- CVE-2018-1560825İzleyin
Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.
OrtaCVSS 6,1Kavram kanıtıEPSS %2manageengine · admanager plus28 Ağu 2018
- CVE-2016-949025İzleyin
ManageEngine Applications Manager versions 12 and 13 suffer from a Reflected Cross-Site Scripting vulnerability
OrtaCVSS 6,1İstismar yokEPSS %2manageengine · applications manager5 Haz 2018
- CVE-2008-047625İzleyin
ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows
OrtaCVSS 6,4İstismar yokEPSS %1manageengine · applications manager29 Oca 2008
- CVE-2008-129924İzleyin
Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Windows allows remote at
OrtaCVSS 6,1İstismar yokEPSS %1manageengine · servicedesk plus12 Mar 2008
- CVE-2020-1955424İzleyin
Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174 when the API key contains an XML-based XSS payload.
OrtaCVSS 6,1İstismar yokEPSS %1manageengine · opmanager21 Eyl 2021
- CVE-2011-275621İzleyin
FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to re
OrtaCVSS 5,0İstismar yokEPSS %2manageengine · servicedesk plus17 Tem 2011