CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93422  CVE-2016-6602  Candidate  ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartext passwords by leveraging access to WEB-INF/conf/securitydbData.xml. NOTE: this issue can be combined with CVE-2016-6601 for a remote exploit.  Assigned (20160804)  None (candidate not yet proposed)    View
93423  CVE-2016-6603  Candidate  ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.  Assigned (20160804)  None (candidate not yet proposed)    View
81695  CVE-2015-4418  Candidate  Zoho NetFlow Analyzer build 10250 and earlier does not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.  Assigned (20150608)  None (candidate not yet proposed)    View
80236  CVE-2015-2959  Candidate  Zoho NetFlow Analyzer build 10250 and earlier does not check for administrative authorization, which allows remote attackers to obtain sensitive information, modify passwords, or remove accounts by leveraging the guest role.  Assigned (20150407)  None (candidate not yet proposed)    View
91709  CVE-2016-4890  Candidate  ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive password information by leveraging access to a cookie.  Assigned (20160517)  None (candidate not yet proposed)    View

Page 18 of 20943, showing 5 records out of 104715 total, starting on record 86, ending on 90

Actions