İçeriğe atla
Noroxi

ManageEngine kayıtları

manageengine üreticisine ait 46 yayımlanmış kayıt.

Tüm kayıtlar

46 kayıt
  • CVE-2015-8249
    61Bu hafta

    The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary fil

    KritikCVSS 9,8SilahlaştırılmışEPSS %74

    manageengine · desktop central27 Eyl 2017

  • CVE-2014-5301
    59Planlayın

    Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to

    YüksekCVSS 8,8SilahlaştırılmışEPSS %78

    manageengine · servicedesk plus28 Ağu 2017

  • CVE-2017-11512
    54Planlayın

    The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the nam

    YüksekCVSS 7,5Kavram kanıtıEPSS %80

    manageengine · servicedesk8 Kas 2017

  • CVE-2014-3996
    42Planlayın

    SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Pro

    YüksekCVSS 7,5SilahlaştırılmışEPSS %38

    manageengine · it3605 Ara 2014

  • CVE-2007-2429
    42Planlayın

    ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command

    KritikCVSS 10,0Kavram kanıtıEPSS %8

    manageengine · passwordmanager pro1 May 2007

  • CVE-2014-9373
    42Planlayın

    Directory traversal vulnerability in the CollectorConfInfoServlet servlet in ManageEngine NetFlow Analyzer allows remote attackers to execut

    KritikCVSS 10,0İstismar yokEPSS %6

    manageengine · netflow analyzer16 Ara 2014

  • CVE-2016-9488
    40Planlayın

    ManageEngine Applications Manager versions 12 and 13 suffer from remote SQL injection vulnerabilities

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    manageengine · applications manager5 Haz 2018

  • CVE-2021-28960
    40Planlayın

    Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input comman

    KritikCVSS 9,8İstismar yokEPSS %2

    manageengine · desktop central21 Eyl 2021

  • CVE-2014-5302
    38İzleyin

    Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9

    YüksekCVSS 8,8İstismar yokEPSS %11

    manageengine · servicedesk plus28 Ağu 2017

  • CVE-2014-5377
    37İzleyin

    ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via

    OrtaCVSS 5,0SilahlaştırılmışEPSS %57

    manageengine · device expert4 Eyl 2014

  • CVE-2014-8499
    37İzleyin

    Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) e

    OrtaCVSS 6,5SilahlaştırılmışEPSS %36

    manageengine · password manager pro17 Kas 2014

  • CVE-2011-2757
    32İzleyin

    Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read

    OrtaCVSS 5,0SilahlaştırılmışEPSS %39

    manageengine · servicedesk plus17 Tem 2011

  • CVE-2014-8678
    32İzleyin

    The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via a crafted filename,

    YüksekCVSS 7,8İstismar yokEPSS %2

    manageengine · oputils25 Kas 2014

  • CVE-2017-11511
    31İzleyin

    The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the fil

    YüksekCVSS 7,5İstismar yokEPSS %4

    manageengine · servicedesk8 Kas 2017

  • CVE-2010-4840
    31İzleyin

    Multiple buffer overflows in the Syslog server in ManageEngine EventLog Analyzer 6.1 allow remote attackers to cause a denial of service (Sy

    YüksekCVSS 7,5İstismar yokEPSS %2

    manageengine · eventlog analyzer27 Eyl 2011

  • CVE-2012-1063
    30İzleyin

    Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL com

    YüksekCVSS 7,5İstismar yokEPSS %1

    manageengine · applications manager13 Şub 2012

  • CVE-2010-1044
    30İzleyin

    SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL commands via the isHttp

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    manageengine · oputils22 Mar 2010

  • CVE-2011-2755
    29İzleyin

    Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to read

    OrtaCVSS 5,0Kavram kanıtıEPSS %31

    manageengine · servicedesk plus17 Tem 2011

  • CVE-2014-9372
    26İzleyin

    Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remot

    OrtaCVSS 6,4İstismar yokEPSS %2

    manageengine · password manager pro16 Ara 2014

  • CVE-2018-15608
    25İzleyin

    Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.

    OrtaCVSS 6,1Kavram kanıtıEPSS %2

    manageengine · admanager plus28 Ağu 2018

  • CVE-2016-9490
    25İzleyin

    ManageEngine Applications Manager versions 12 and 13 suffer from a Reflected Cross-Site Scripting vulnerability

    OrtaCVSS 6,1İstismar yokEPSS %2

    manageengine · applications manager5 Haz 2018

  • CVE-2008-0476
    25İzleyin

    ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows

    OrtaCVSS 6,4İstismar yokEPSS %1

    manageengine · applications manager29 Oca 2008

  • CVE-2008-1299
    24İzleyin

    Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Windows allows remote at

    OrtaCVSS 6,1İstismar yokEPSS %1

    manageengine · servicedesk plus12 Mar 2008

  • CVE-2020-19554
    24İzleyin

    Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174 when the API key contains an XML-based XSS payload.

    OrtaCVSS 6,1İstismar yokEPSS %1

    manageengine · opmanager21 Eyl 2021

  • CVE-2011-2756
    21İzleyin

    FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to re

    OrtaCVSS 5,0İstismar yokEPSS %2

    manageengine · servicedesk plus17 Tem 2011