CVE List

Id CVE No. Status Description Phase Votes Comments Actions
91708  CVE-2016-4889  Candidate  ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict access to unknown functions.  Assigned (20160517)  None (candidate not yet proposed)    View
78757  CVE-2015-1480  Candidate  ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive ticket information via a (1) getTicketData action to servlet/AJaxServlet or a direct request to (2) swf/flashreport.swf, (3) reports/flash/details.jsp, or (4) reports/CreateReportTable.jsp.  Assigned (20150204)  None (candidate not yet proposed)    View
85042  CVE-2015-7765  Candidate  ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser account, which allows remote authenticated users to obtain administrator access by leveraging knowledge of this password.  Assigned (20151009)  None (candidate not yet proposed)    View
73342  CVE-2014-6043  Candidate  ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote authenticated users to obtain access to the database via a direct request to event/runQuery.do.  Assigned (20140901)  None (candidate not yet proposed)    View
84664  CVE-2015-7387  Candidate  ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions and execute arbitrary SQL commands via an allowed query followed by a disallowed one in the query parameter to event/runQuery.do, as demonstrated by "SELECT 1;INSERT INTO."  Assigned (20150928)  None (candidate not yet proposed)    View

Page 19 of 20943, showing 5 records out of 104715 total, starting on record 91, ending on 95

Actions