Vulnerabilities
Vulnerable Software
Zohocorp:  Security Vulnerabilities
The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injection.
CVSS Score
9.8
EPSS Score
0.023
Published
2019-05-02
The "default reports" feature in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123218 is vulnerable to SQL Injection.
CVSS Score
9.8
EPSS Score
0.128
Published
2019-05-02
Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Trojan horse file into the permissive bin directory.
CVSS Score
7.0
EPSS Score
0.001
Published
2019-04-30
Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API.
CVSS Score
6.1
EPSS Score
0.026
Published
2019-04-25
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect password, in an mc/ login attempt within a different browser tab.
CVSS Score
8.8
EPSS Score
0.091
Published
2019-04-24
Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious file via the "Execute Program Action(s)" feature.
CVSS Score
9.8
EPSS Score
0.047
Published
2019-04-23
An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For example, the attacker can subsequently write arbitrary text to a .vbs file.
CVSS Score
9.8
EPSS Score
0.194
Published
2019-04-22
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify any active account.
CVSS Score
4.3
EPSS Score
0.139
Published
2019-04-04
ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.
CVSS Score
8.8
EPSS Score
0.003
Published
2019-03-25
ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do.
CVSS Score
6.5
EPSS Score
0.006
Published
2019-03-25


Contact Us

Shodan ® - All rights reserved