VYPR

Desktopcentral

by Manageengine

CVEs (10)

  • CVE-2015-8249CriSep 28, 2017
    risk 0.73cvss 9.8epss 0.80

    The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter.

  • CVE-2017-11346CriJul 17, 2017
    risk 0.69cvss 9.8epss 0.25

    Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos.

  • CVE-2015-2560CriAug 2, 2017
    risk 0.65cvss 9.8epss 0.20

    Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet.

  • CVE-2014-3996Dec 5, 2014
    risk 0.09cvss epss 0.71

    SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90043, Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition…

  • CVE-2018-12999Jun 29, 2018
    risk 0.01cvss epss 0.10

    Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web server without login by sending a specially crafted request to the server with a computerName=../ substring to the /agenttrayicon…

  • CVE-2023-4769Nov 3, 2023
    risk 0.00cvss epss 0.00

    A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerability could allow an authenticated attacker to launch targeted attacks, such as a cross-port attack, service enumeration and other…

  • CVE-2023-4768Nov 3, 2023
    risk 0.00cvss epss 0.01

    A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in…

  • CVE-2023-4767Nov 3, 2023
    risk 0.00cvss epss 0.01

    A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in…

  • CVE-2018-16833Sep 21, 2018
    risk 0.00cvss epss 0.03

    Zoho ManageEngine Desktop Central 10.0.271 has XSS via the "Features & Articles" search field to the /advsearch.do?SUBREQUEST=XMLHTTP URI.

  • CVE-2018-8722Mar 15, 2018
    risk 0.00cvss epss 0.02

    Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026.