VYPR

Manageengine Applications Manager

Sign in to watch

by Zohocorp

CVEs (8)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-16543Cri0.679.80.02Nov 5, 2017Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.
CVE-2017-16851Cri0.659.80.12Nov 16, 2017Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter.
CVE-2017-16850Cri0.659.80.12Nov 16, 2017Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfiles action.
CVE-2017-16849Cri0.659.80.12Nov 16, 2017Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoard forpage parameter.
CVE-2017-16847Cri0.659.80.12Nov 16, 2017Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a showPlasmaView action.
CVE-2017-16846Cri0.659.80.12Nov 16, 2017Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter.
CVE-2017-16848Cri0.649.80.09Nov 16, 2017Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter.
CVE-2017-16542Hig0.608.80.01Nov 5, 2017Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.