Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2010-3272

accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 makes it easier for remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, via a modified (1) Hide_Captcha or (2) quesList parameter in a validateAll action.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.091
EPSS Ranking 92.3%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2010-3272


Contact Us

Shodan ® - All rights reserved