
CVE-2018-17596 – ManageEngine AssetExplorer 6.2.0 Cross Site Scripting
https://notcve.org/view.php?id=CVE-2018-17596
29 Sep 2018 — In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ciName or assetName parameter. En Zoho ManageEngine AssetExplorer, se ha descubierto una vulnerabilidad de Cross-Site Scripting (XSS) persistente en la versión 6.2.0 mediante los parámetros ciName o assetName en /AssetDef.do. • https://packetstorm.news/files/id/149597 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2015-5061
https://notcve.org/view.php?id=CVE-2015-5061
24 Jun 2015 — Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 and earlier allows remote authenticated users with permissions to add new vendors to inject arbitrary web script or HTML via the organizationName parameter to VendorDef.do. Vulnerabilidad de XSS en Zoho ManageEngine AssetExplorer 6.1 service pack 6112 y anteriores permite a usuarios remotos autenticados con permisos para añadir nuevos proveedores inyectar secuencias de comandos web arbitrarios o HTML a través d... • http://www.securityfocus.com/bid/75411 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2015-2169 – ManageEngine Asset Explorer 6.1 - Persistent Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2015-2169
24 Jun 2015 — Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 allows remote attackers to inject arbitrary web script or HTML via a Publisher registry entry, which is not properly handled when the machine is scanned. Vulnerabilidad de XSS en Zoho ManageEngine AssetExplorer 6.1 service pack 6112 permite a atacantes remotos inyectar secuencias de comandos web arbitrarios o HTML a través de una entrada del registro Publisher, la cual no se maneja correctamente cuando la máqui... • https://packetstorm.news/files/id/132433 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2012-5956
https://notcve.org/view.php?id=CVE-2012-5956
11 Dec 2012 — Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine AssetExplorer 5.6 before service pack 5614 allow remote attackers to inject arbitrary web script or HTML via fields in XML asset data to discoveryServlet/WsDiscoveryServlet, as demonstrated by the DocRoot/Computer_Information/output element. Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en ManageEngine AssetExplorer v5.6 antes de service pack 5614 permite a atacantes remotos inyectar secuencias d... • http://www.kb.cert.org/vuls/id/571068 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •