Page 3 of 26 results (0.002 seconds)

CVSS: 6.1EPSS: 1%CPEs: 6EXPL: 1

11 Jul 2019 — An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType. Se detectó un problema en ManageEngine AssetExplorer de Zoho. Se presenta un problema de tipo XSS por medio del archivo SoftwareListView.do con el parámetro swType o swComplianceType. • http://www.securityfocus.com/bid/109364 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 1%CPEs: 6EXPL: 1

11 Jul 2019 — An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via ResourcesAttachments.jsp with the parameter pageName. Se detectó un problema en ManageEngine AssetExplorer de Zoho. Se presenta un problema de tipo XSS por medio del archivo ResourcesAttachments.jsp con el parámetro pageName. • http://www.securityfocus.com/bid/109364 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 2%CPEs: 1EXPL: 1

29 Sep 2018 — In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ciName or assetName parameter. En Zoho ManageEngine AssetExplorer, se ha descubierto una vulnerabilidad de Cross-Site Scripting (XSS) persistente en la versión 6.2.0 mediante los parámetros ciName o assetName en /AssetDef.do. • https://packetstorm.news/files/id/149597 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 2

24 Jun 2015 — Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 and earlier allows remote authenticated users with permissions to add new vendors to inject arbitrary web script or HTML via the organizationName parameter to VendorDef.do. Vulnerabilidad de XSS en Zoho ManageEngine AssetExplorer 6.1 service pack 6112 y anteriores permite a usuarios remotos autenticados con permisos para añadir nuevos proveedores inyectar secuencias de comandos web arbitrarios o HTML a través d... • http://www.securityfocus.com/bid/75411 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 4%CPEs: 1EXPL: 4

24 Jun 2015 — Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 allows remote attackers to inject arbitrary web script or HTML via a Publisher registry entry, which is not properly handled when the machine is scanned. Vulnerabilidad de XSS en Zoho ManageEngine AssetExplorer 6.1 service pack 6112 permite a atacantes remotos inyectar secuencias de comandos web arbitrarios o HTML a través de una entrada del registro Publisher, la cual no se maneja correctamente cuando la máqui... • https://packetstorm.news/files/id/132433 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 1%CPEs: 1EXPL: 0

11 Dec 2012 — Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine AssetExplorer 5.6 before service pack 5614 allow remote attackers to inject arbitrary web script or HTML via fields in XML asset data to discoveryServlet/WsDiscoveryServlet, as demonstrated by the DocRoot/Computer_Information/output element. Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en ManageEngine AssetExplorer v5.6 antes de service pack 5614 permite a atacantes remotos inyectar secuencias d... • http://www.kb.cert.org/vuls/id/571068 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •