
CVE-2020-10189 – Zoho ManageEngine Desktop Central File Upload Vulnerability
https://notcve.org/view.php?id=CVE-2020-10189
06 Mar 2020 — Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets. Zoho ManageEngine Desktop Central anterior a la versión 10.0.474 permite la ejecución remota de código debido a la deserialización de datos no seguros en getChartImage en la clase FileStorage. Esto está relacionado con los servlets CewolfServlet y MDMLogUploaderServlet. Z... • https://packetstorm.news/files/id/156730 • CWE-502: Deserialization of Untrusted Data •

CVE-2013-7390 – ManageEngine Desktop Central - Arbitrary File Upload / Remote Code Execution
https://notcve.org/view.php?id=CVE-2013-7390
27 Jan 2020 — Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the webroot. Una vulnerabilidad de carga de archivos sin restricciones en la función AgentLogUploadServlet en ManageEngine DesktopCentral versiones 7.x y 8.0.0 anterior al build 80293, permite a atacantes remotos ejecutar código arbitrari... • https://www.exploit-db.com/exploits/34518 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2018-13411
https://notcve.org/view.php?id=CVE-2018-13411
12 Sep 2018 — An issue was discovered in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version. Se detectó un problema en Zoho ManageEngine Desktop Central antes de la versión 10.0.282. Un logotipo de la empresa sobre el que se puede hacer clic en una ventana que se ejecuta como SISTEMA puede ser abusado para escalar privilegios. • http://www.securityfocus.com/bid/105348 • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2018-13412
https://notcve.org/view.php?id=CVE-2018-13412
12 Sep 2018 — An issue was discovered in the Self Service Portal in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version. Se detectó un problema en el Portal de Autoservicio en Zoho ManageEngine Desktop Central antes de la versión 10.0.282. Un logotipo de la empresa sobre el que se puede hacer clic en una ventana que se ejecuta como SISTEMA puede ser abusado para escalar privil... • http://www.securityfocus.com/bid/105348 • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2018-11716
https://notcve.org/view.php?id=CVE-2018-11716
16 Jul 2018 — An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled devices, cleartext passwords, patching level, etc.) via a GET request on port 8022, 8443, or 8444. Se ha descubierto un problema en Zoho ManageEngine Desktop Central 100230. Hay un acceso remoto no autenticado a todos los archivos de registro de una instancia Desktop ... • https://blog.netxp.fr/manageengine-deep-exploitation • CWE-532: Insertion of Sensitive Information into Log File •

CVE-2018-11717
https://notcve.org/view.php?id=CVE-2018-11717
16 Jul 2018 — An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base64 encoded Password/Username of AD accounts, the cleartext Password/Username and mail settings of the EAS account (an AD account used to send mail), the cleartext password of recovery_password of Android devices, the cleartext password of account "set", the location of devices enrolled in the platform (with UUID ... • https://blog.netxp.fr/manageengine-deep-exploitation • CWE-532: Insertion of Sensitive Information into Log File •

CVE-2018-8722
https://notcve.org/view.php?id=CVE-2018-8722
15 Mar 2018 — Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026. Zoho ManageEngine Desktop Central, en su versión 9.1.0 build 91099, tiene múltiples problemas de Cross-Site Scripting (XSS) que se solucionaron en la build 92026. • https://www.manageengine.com/products/desktop-central/cross-site-scripting-vulnerability.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-11346 – ManageEngine Desktop Central 10 Build 100087 - Remote Code Execution
https://notcve.org/view.php?id=CVE-2017-11346
16 Jul 2017 — Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos. Desktop Central antes del build 100092 de Zoho ManageEngine, permite a los atacantes remotos ejecutar código arbitrario por medio de vectores que involucran la carga de videos de soporte al usuario. • https://www.exploit-db.com/exploits/42358 • CWE-20: Improper Input Validation •

CVE-2015-2560 – Manage Engine Desktop Central 9 Unauthorized Administrative Password Reset
https://notcve.org/view.php?id=CVE-2015-2560
27 Mar 2015 — Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet. El Desktop Central 9 de ManageEngine anterior a Build 90135 permite que atacantes remotos cambien las contraseñas de los usuarios con un rol de administrador mediante una operación addOrModifyUser en servlets/DCOperationsServlet. A remote unauthenticated user can change the password of any Manage Engine Desktop C... • https://packetstorm.news/files/id/131062 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2014-9331 – ManageEngine Desktop Central 9 Build 90087 - Cross-Site Request Forgery
https://notcve.org/view.php?id=CVE-2014-9331
03 Feb 2015 — Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an addUser action to STATE_ID/1417736606982/roleMgmt.do. Vulnerabilidad de CSRF en ZOHO ManageEngine Desktop Central anterior a 9 build 90130 permite a atacantes remotos secuestrar la autenticación de administradores para solicitudes que añaden una cuenta de administrador a través de... • https://www.exploit-db.com/exploits/35980 • CWE-352: Cross-Site Request Forgery (CSRF) •