NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
28217  CVE-2015-7765  ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser account, which allows remote authenticated users to obtain administrator access by leveraging knowledge of this password.    High  2017-01-19  2015-10-09  View
23791  CVE-2015-1480  ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive ticket information via a (1) getTicketData action to servlet/AJaxServlet or a direct request to (2) swf/flashreport.swf, (3) reports/flash/details.jsp, or (4) reports/CreateReportTable.jsp.    Medium  2017-01-19  2015-02-04  View
85318  CVE-2016-4889  ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict access to unknown functions.    6.5  Medium  2017-04-27  2017-04-21  View
85319  CVE-2016-4890  ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive password information by leveraging access to a cookie.    Medium  2017-04-27  2017-04-21  View
24908  CVE-2015-2959  Zoho NetFlow Analyzer build 10250 and earlier does not check for administrative authorization, which allows remote attackers to obtain sensitive information, modify passwords, or remove accounts by leveraging the guest role.    7.5  High  2017-01-19  2016-12-30  View

Page 17654 of 17672, showing 5 records out of 88360 total, starting on record 88266, ending on 88270

Actions