VendorsZoho Corpmanageengine_desktop_central10.0.124
Vulnerabilities

Zoho Corp ZohoCorp ManageEngine Desktop Central 10.0.124

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2018-5337
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NAME field when modifying existing scripts.
Published 2018-04-18 · Modified
9.8EPSS 0.094
CVE-2018-5338
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanism.
Published 2018-04-18 · Modified
9.8EPSS 0.088
CVE-2018-5341
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploading and modifying scripts.
Published 2018-04-18 · Modified
9.8EPSS 0.081
CVE-2018-5339
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions.
Published 2018-04-18 · Modified
9.8EPSS 0.075
CVE-2018-5340
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: database access using a superuser account (specifically, an account with permission to write to the filesystem via SQL queries).
Published 2018-04-18 · Modified
7.2EPSS 0.051
CVE-2018-5342
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: network services (Desktop Central and PostgreSQL) running with a superuser account.
Published 2018-04-18 · Modified
7.2EPSS 0.037