Skip to main content

Vendor/product archive

zohocorp / manageengine_eventlog_analyzer CVEs

Beta · best-effort

19 CVEs tagged to zohocorp / manageengine_eventlog_analyzer2 Critical, 7 High, 10 Medium, 0 Low, 0 Unrated.

CVE-2021-28959

Published Apr 30, 2021

Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive. This leads to remote code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-6038

Published Jan 13, 2020

Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLog Analyzer 10.0 Build 10000.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19774

Published Dec 13, 2019

An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10076

Published Jul 2, 2018

An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. A Cross-Site Scripting vulnerability allows a remote attacker to inject arbitrary web script or HTML via the…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10075

Published Jul 2, 2018

Cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer 11.12 allows remote attackers to inject arbitrary web script or HTML via the import logs feature.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-8721

Published Mar 15, 2018

Zoho ManageEngine EventLog Analyzer version 11.0 build 11000 has Stored XSS related to the index2.do?url=editAlertForm&tab=alert&alert=profile URI and the Edit Alert Profile screen

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-7405

Published Mar 13, 2018

Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11687

Published Jul 27, 2017

Multiple Persistent cross-site scripting (XSS) vulnerabilities in Event log parsing and Display functions in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attack…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11686

Published Jul 27, 2017

Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the ne…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11685

Published Jul 27, 2017

Multiple Reflective cross-site scripting (XSS) vulnerabilities in search and display of event data in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7387

Published Sep 28, 2015

ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions and execute arbitrary SQL commands via an allowed query fo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-6037

Published Oct 26, 2014

Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 allows remote attackers to execute arbitrary…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-6043

Published Sep 11, 2014

ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote authenticated users to obtain…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4930

Published Aug 29, 2014

Multiple cross-site scripting (XSS) vulnerabilities in event/index2.do in ManageEngine EventLog Analyzer before 9.0 build 9002 allow remote attackers to inject arbitrary web scrip…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-5103

Published Jul 25, 2014

Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine EventLog Analyzer 9 build 9000 allows remote attackers to inject arbitrary web script or HTML via the j_username para…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1