NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
14686 | CVE-2010-3273 | ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allows remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, by providing a user id to accounts/ValidateUser, and then providing a new password to accounts/ResetResult. | 2 | 5 | Medium | 2017-01-18 | 2011-09-21 | View | |
86011 | CVE-2017-7213 | Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified vectors. | 2 | 10 | High | 2017-05-27 | 2017-05-22 | View | |
87843 | CVE-2017-11346 | Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos. | 2017-07-18 | 2017-07-17 | View | ||||
27997 | CVE-2015-7387 | ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions and execute arbitrary SQL commands via an allowed query followed by a disallowed one in the query parameter to event/runQuery.do, as demonstrated by "SELECT 1;INSERT INTO." | 2 | 7.5 | High | 2017-01-19 | 2016-12-07 | View | |
33662 | CVE-2014-6043 | ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote authenticated users to obtain access to the database via a direct request to event/runQuery.do. | 2 | 6.5 | Medium | 2017-01-19 | 2014-09-12 | View |
Page 17653 of 17672, showing 5 records out of 88360 total, starting on record 88261, ending on 88265