Manageengine Admanager Plus
by Zohocorp
CVEs (66)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-41904 | Med | 0.35 | 5.4 | 0.02 | Sep 27, 2023 | Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs. | ||
| CVE-2021-37922 | Med | 0.35 | 5.3 | 0.02 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to path traversal which allows copying of files from one directory to another. | ||
| CVE-2023-39912 | Med | 0.32 | 4.9 | 0.04 | Aug 31, 2023 | Zoho ManageEngine ADManager Plus before 7203 allows Help Desk Technician users to read arbitrary files on the machine where this product is installed. | ||
| CVE-2023-35786 | Med | 0.32 | 4.9 | 0.03 | Jul 5, 2023 | Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files. | ||
| CVE-2015-1026 | 0.00 | — | 0.04 | Mar 11, 2015 | Multiple cross-site scripting (XSS) vulnerabilities in ZOHO ManageEngine ADManager Plus before 6.2 Build 6270 allow remote attackers to inject arbitrary web script or HTML via the (1) technicianSearchText parameter to the Help Desk Technician page or (2) rolesSearchText… | |||
| CVE-2010-5050 | 0.00 | — | 0.03 | Nov 23, 2011 | Cross-site scripting (XSS) vulnerability in jsp/admin/tools/remote_share.jsp in ManageEngine ADManager Plus 4.4.0 allows remote attackers to inject arbitrary web script or HTML via the computerName parameter. NOTE: the provenance of this information is unknown; the details are… |
- risk 0.35cvss 5.4epss 0.02
Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs.
- risk 0.35cvss 5.3epss 0.02
Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to path traversal which allows copying of files from one directory to another.
- risk 0.32cvss 4.9epss 0.04
Zoho ManageEngine ADManager Plus before 7203 allows Help Desk Technician users to read arbitrary files on the machine where this product is installed.
- risk 0.32cvss 4.9epss 0.03
Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.
- CVE-2015-1026Mar 11, 2015risk 0.00cvss —epss 0.04
Multiple cross-site scripting (XSS) vulnerabilities in ZOHO ManageEngine ADManager Plus before 6.2 Build 6270 allow remote attackers to inject arbitrary web script or HTML via the (1) technicianSearchText parameter to the Help Desk Technician page or (2) rolesSearchText…
- CVE-2010-5050Nov 23, 2011risk 0.00cvss —epss 0.03
Cross-site scripting (XSS) vulnerability in jsp/admin/tools/remote_share.jsp in ManageEngine ADManager Plus 4.4.0 allows remote attackers to inject arbitrary web script or HTML via the computerName parameter. NOTE: the provenance of this information is unknown; the details are…
Page 4 of 4