Skip to main content

Vendor/product archive

manageengine / applications_manager CVEs

Beta · best-effort

8 CVEs tagged to manageengine / applications_manager1 Critical, 1 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2016-9490

Published Jun 5, 2018

ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from a Reflected Cross-Site Scripting vulnerability. Applications Manager is prone to a Cross-Site S…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9488

Published Jun 5, 2018

ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /se…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1063

Published Feb 14, 2012

Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL commands via the (1) viewId parameter to f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1062

Published Feb 14, 2012

Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to inject arbitrary web script or HTML via the (1) per…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1566

Published Mar 31, 2008

Cross-site scripting (XSS) vulnerability in Search.do in ManageEngine Applications Manager 8.x allows remote attackers to inject arbitrary web script or HTML via the query paramet…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0474

Published Jan 29, 2008

Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 8.1 build 8100 allow remote attackers to inject arbitrary web script or HTML via the (1) s…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0475

Published Jan 29, 2008

ManageEngine Applications Manager 8.1 build 8100 allows remote attackers to obtain sensitive information ( Home->Summary) via an invalid URI, as demonstrated by the "/-" URI. NOT…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0476

Published Jan 29, 2008

ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows remote attackers to obtain sensitive in…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1