Skip to main content

Vendor archive

manageengine CVEs

Beta · best-effort

46 CVEs tagged to vendor manageengine5 Critical, 9 High, 31 Medium, 1 Low, 0 Unrated.

CVE-2020-19554

Published Sep 21, 2021

Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174 when the API key contains an XML-based XSS payload.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28960

Published Sep 21, 2021

Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-demand operations.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-9490

Published Jun 5, 2018

ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from a Reflected Cross-Site Scripting vulnerability. Applications Manager is prone to a Cross-Site S…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9488

Published Jun 5, 2018

ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /se…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-11512

Published Nov 8, 2017

The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name parameter for the download-snapshot U…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-11511

Published Nov 8, 2017

The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filepath parameter for the download-file U…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8249

Published Sep 28, 2017

The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-1480

Published Feb 4, 2015

ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive ticket information via a (1) getTicketData action to servlet/A…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9373

Published Dec 16, 2014

Directory traversal vulnerability in the CollectorConfInfoServlet servlet in ManageEngine NetFlow Analyzer allows remote attackers to execute arbitrary code via a .. (dot dot) in…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-9372

Published Dec 16, 2014

Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remote attackers to delete arbitrary files v…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8678

Published Nov 25, 2014

The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via a crafted filename, related to "saveFile."

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-8499

Published Nov 17, 2014

Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allow remo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-5377

Published Sep 4, 2014

ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct request.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4891

Published Sep 10, 2012

Cross-site scripting (XSS) vulnerability in fw/index2.do in ManageEngine Firewall Analyzer 7.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4889

Published Sep 10, 2012

Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Firewall Analyzer 7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) subTab or (2) t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2585

Published Aug 12, 2012

Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ServiceDesk Plus 8.1 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body w…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1063

Published Feb 14, 2012

Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL commands via the (1) viewId parameter to f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1062

Published Feb 14, 2012

Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to inject arbitrary web script or HTML via the (1) per…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1049

Published Feb 13, 2012

Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ADManager Plus 5.2 Build 5210 allow remote attackers to inject arbitrary web script or HTML via the (1) domainN…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4841

Published Sep 27, 2011

Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine EventLog Analyzer 6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) HOST_ID, (2) OS…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4840

Published Sep 27, 2011

Multiple buffer overflows in the Syslog server in ManageEngine EventLog Analyzer 6.1 allow remote attackers to cause a denial of service (SysEvttCol.exe process crash) or possibly…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 46 CVEsPage 1 of 2