CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
93422 | CVE-2016-6602 | Candidate | ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartext passwords by leveraging access to WEB-INF/conf/securitydbData.xml. NOTE: this issue can be combined with CVE-2016-6601 for a remote exploit. | Assigned (20160804) | None (candidate not yet proposed) | View | |
93423 | CVE-2016-6603 | Candidate | ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header. | Assigned (20160804) | None (candidate not yet proposed) | View | |
81695 | CVE-2015-4418 | Candidate | Zoho NetFlow Analyzer build 10250 and earlier does not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation. | Assigned (20150608) | None (candidate not yet proposed) | View | |
80236 | CVE-2015-2959 | Candidate | Zoho NetFlow Analyzer build 10250 and earlier does not check for administrative authorization, which allows remote attackers to obtain sensitive information, modify passwords, or remove accounts by leveraging the guest role. | Assigned (20150407) | None (candidate not yet proposed) | View | |
91709 | CVE-2016-4890 | Candidate | ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive password information by leveraging access to a cookie. | Assigned (20160517) | None (candidate not yet proposed) | View |
Page 18 of 20943, showing 5 records out of 104715 total, starting on record 86, ending on 90