Zohocorp
Zohocorp Manageengine Eventlog Analyzer: vulnerabilidades y CVE
Zohocorp Manageengine Eventlog Analyzer tiene 19 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE19
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-35785 | Alta (8.1) | 2.4% | — | 28 ago 2023 | Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data… |
| CVE-2021-28959 | Crítica (9.8) | 17% | — | 30 abr 2021 | Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive. This leads to remote code execution. |
| CVE-2020-24786 | Crítica (9.8) | 13% | — | 31 ago 2020 | An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before build number 6033,… |
| CVE-2014-6039 | Alta (7.5) | 69% | — | 13 ene 2020 | ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000. |
| CVE-2014-6038 | Alta (7.5) | 73% | — | 13 ene 2020 | Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLog Analyzer 10.0 Build 10000. |
| CVE-2019-19774 | Alta (8.8) | 13% | — | 13 dic 2019 | An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it is possible to bypass the security… |
| CVE-2019-12133 | Alta (7.8) | 1.7% | — | 18 jun 2019 | Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said… |
| CVE-2018-10076 | Media (6.1) | 1.3% | — | 2 jul 2018 | An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. A Cross-Site Scripting vulnerability allows a remote attacker to inject arbitrary web script or HTML via the search functionality (the search box of… |
| CVE-2018-10075 | Media (6.1) | 1.3% | — | 2 jul 2018 | Cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer 11.12 allows remote attackers to inject arbitrary web script or HTML via the import logs feature. |
| CVE-2018-8721 | Media (6.1) | 1.9% | — | 15 mar 2018 | Zoho ManageEngine EventLog Analyzer version 11.0 build 11000 has Stored XSS related to the index2.do?url=editAlertForm&tab=alert&alert=profile URI and the Edit Alert Profile screen |
| CVE-2018-7405 | Media (6.1) | 1.3% | — | 13 mar 2018 | Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2017-11687 | Media (6.1) | 1.3% | — | 27 jul 2017 | Multiple Persistent cross-site scripting (XSS) vulnerabilities in Event log parsing and Display functions in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or… |
| CVE-2017-11686 | Media (6.1) | 2.3% | — | 27 jul 2017 | Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the password is… |
| CVE-2017-11685 | Media (6.1) | 1.3% | — | 27 jul 2017 | Multiple Reflective cross-site scripting (XSS) vulnerabilities in search and display of event data in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML, as… |
| CVE-2015-7387 | Alta (7.5) | 80% | — | 28 sept 2015 | ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions and execute arbitrary SQL commands via an allowed query followed by a disallowed one in the query… |
| CVE-2014-6037 | Alta (7.5) | 84% | — | 26 oct 2014 | Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 allows remote attackers to execute arbitrary code by uploading a ZIP file which… |
| CVE-2014-6043 | Media (6.5) | 13% | — | 11 sept 2014 | ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote authenticated users to obtain access to the database via a direct… |
| CVE-2014-4930 | Media (4.3) | 3.6% | — | 29 ago 2014 | Multiple cross-site scripting (XSS) vulnerabilities in event/index2.do in ManageEngine EventLog Analyzer before 9.0 build 9002 allow remote attackers to inject arbitrary web script or HTML via the (1) width, (2) height,… |
| CVE-2014-5103 | Media (4.3) | 3.5% | — | 25 jul 2014 | Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine EventLog Analyzer 9 build 9000 allows remote attackers to inject arbitrary web script or HTML via the j_username parameter to event/j_security_check. Fixed… |
Otros productos de Zohocorp
Manageengine Opmanager · 63Manageengine Applications Manager · 59Manageengine Adselfservice Plus · 56Manageengine Adaudit Plus · 53Manageengine Admanager Plus · 53Manageengine Servicedesk Plus · 50Manageengine Desktop Central · 48Manageengine Supportcenter Plus · 31Manageengine Netflow Analyzer · 30Manageengine Exchange Reporter Plus · 28Manageengine Assetexplorer · 26Manageengine Servicedesk Plus MSP · 26