Vulnerabilities (CVE)

Filtered by vendor Zohocorp Subscribe
Total 488 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-18980 1 Zohocorp 2 Manageengine Network Configuration Manager, Manageengine Opmanager 2024-11-21 5.0 MEDIUM 7.5 HIGH
An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local files to an arbitrary remote FTP server.
CVE-2018-18949 1 Zohocorp 1 Manageengine Opmanager 2024-11-21 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings.
CVE-2018-18716 1 Zohocorp 1 Manageengine Opmanager 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine OpManager 12.3 before 123219 has a Self XSS Vulnerability.
CVE-2018-18715 1 Zohocorp 1 Manageengine Opmanager 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine OpManager 12.3 before 123219 has stored XSS.
CVE-2018-18475 1 Zohocorp 1 Manageengine Opmanager 2024-11-21 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload.
CVE-2018-18262 1 Zohocorp 1 Manageengine Opmanager 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine OpManager 12.3 before build 123214 has XSS.
CVE-2018-17596 1 Zohocorp 1 Manageengine Assetexplorer 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ciName or assetName parameter.
CVE-2018-17283 1 Zohocorp 1 Manageengine Opmanager 2024-11-21 5.0 MEDIUM 7.5 HIGH
Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via /api/json/v2/admin/addUser or conduct a SQL Injection attack via the /api/json/device/setManaged name parameter.
CVE-2018-17243 1 Zohocorp 1 Manageengine Opmanager 2024-11-21 7.5 HIGH 9.8 CRITICAL
Global Search in Zoho ManageEngine OpManager before 12.3 123205 allows SQL Injection.
CVE-2018-16965 1 Zohocorp 1 Manageengine Supportcenter Plus 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
In Zoho ManageEngine SupportCenter Plus before 8.1 Build 8109, there is HTML Injection and Stored XSS via the /ServiceContractDef.do contractName parameter.
CVE-2018-16833 1 Zohocorp 1 Manageengine Desktop Central 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine Desktop Central 10.0.271 has XSS via the "Features & Articles" search field to the /advsearch.do?SUBREQUEST=XMLHTTP URI.
CVE-2018-16364 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 9.3 HIGH 8.1 HIGH
A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload on an SMB share.
CVE-2018-15740 1 Zohocorp 1 Manageengine Admanager Plus 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.
CVE-2018-15169 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to inject arbitrary web script or HTML via the /deleteMO.do method parameter.
CVE-2018-15168 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 7.5 HIGH 9.8 CRITICAL
A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplaynames.do?method=editDisplaynames GET request.
CVE-2018-13412 1 Zohocorp 1 Manageengine Desktop Central 2024-11-21 7.2 HIGH 7.8 HIGH
An issue was discovered in the Self Service Portal in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version.
CVE-2018-13411 1 Zohocorp 1 Manageengine Desktop Central 2024-11-21 9.0 HIGH 8.8 HIGH
An issue was discovered in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version.
CVE-2018-13050 1 Zohocorp 1 Manageengine Applications Manager 2024-11-21 7.5 HIGH 9.8 CRITICAL
A SQL Injection vulnerability exists in Zoho ManageEngine Applications Manager 13.x before build 13800 via the j_username parameter in a /j_security_check POST request.
CVE-2018-12999 1 Zohocorp 1 Manageengine Desktop Central 2024-11-21 6.4 MEDIUM 7.5 HIGH
Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web server without login by sending a specially crafted request to the server with a computerName=../ substring to the /agenttrayicon URI.
CVE-2018-12998 1 Zohocorp 5 Firewall Analyzer, Manageengine Netflow Analyzer, Manageengine Network Configuration Manager and 2 more 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows remote attackers to inject arbitrary web script or HTML via the parameter 'operation' to /servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet.