CVE-2012-1049 – ManageEngine ADManager Plus 5.2 Build 5210 - 'domainName' Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2012-1049
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ADManager Plus 5.2 Build 5210 allow remote attackers to inject arbitrary web script or HTML via the (1) domainName parameter to jsp/AddDC.jsp or (2) operation parameter to DomainConfig.do. Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en ManageEngine ADManager Plus v5.2 Build 5210 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro (1) nombreDominio de jsp / AddDC.jsp o (2) los parámetros de funcionamiento de DomainConfig.do. • https://www.exploit-db.com/exploits/36667 https://www.exploit-db.com/exploits/36666 http://packetstormsecurity.org/files/109528 http://secunia.com/advisories/47887 http://www.securityfocus.com/bid/51893 http://www.zeroscience.mk/en/vulnerabilities/ZSL-2012-5070.php https://exchange.xforce.ibmcloud.com/vulnerabilities/73039 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2010-4840
https://notcve.org/view.php?id=CVE-2010-4840
Multiple buffer overflows in the Syslog server in ManageEngine EventLog Analyzer 6.1 allow remote attackers to cause a denial of service (SysEvttCol.exe process crash) or possibly execute arbitrary code via a long Syslog PRI message header to UDP port (1) 513 or (2) 514. Fixed in 7.2 Build 7020. Múltiples desbordamientos de búfer en el servidor Syslog en ManageEngine EventLog Analyzer 6.1 permiten a los atacantes remotos causar una denegación de servicio (bloqueo del proceso SysEvttCol.exe) o posiblemente ejecutar código arbitrario a través de un encabezado de mensaje Syslog PRI largo al puerto UDP (1) 513 o (2 ) 514. Solucionado en 7.2 Build 7020. • http://www.solutionary.com/index/SERT/Vuln-Disclosures/ManageEngine-Eventlog-Analyzer-Syslog-Renite-DoS-vuln.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2010-4841
https://notcve.org/view.php?id=CVE-2010-4841
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine EventLog Analyzer 6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) HOST_ID, (2) OS, (3) GROUP, (4) exportFile, (5) load, (6) type, or (7) tab parameter to INDEX.do, the (8) reported parameter to INDEX2.do, the (9) gId parameter to hostlist.do, the (10) newWindow parameter to globalSettings.do, or the (11) STATUS parameter to enableHost.do. Fixed in Build 9000. Múltiples vulnerabilidades cross-site scripting (XSS) en ManageEngine EventLog Analyzer 6.1 permiten a los atacantes remotos inyectar script web arbitrario o HTML a través del (1) HOST_ID, (2) OS, (3) GROUP, (4) exportFile, (5) load , (6) tipo o (7) parámetro de pestaña a INDEX.do, el (8) parámetro informado a INDEX2.do, el parámetro (9) gId a hostlist.do, el parámetro (10) newWindow a globalSettings.do, o el parámetro (11) STATUS para enableHost.do. Corregido en Build 9000. • http://www.solutionary.com/index/SERT/Vuln-Disclosures/ManageEngine-XSS-vulnerabilities.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2011-1509
https://notcve.org/view.php?id=CVE-2011-1509
The encryptPassword function in Login.js in ManageEngine ServiceDesk Plus (SDP) 8012 and earlier uses a Caesar cipher for encryption of passwords in cookies, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. La función EncryptPassword en Login.js en ManageEngine ServiceDesk Plus (SDP) v8012 y anteriores utiliza un cifrado César para el cifrado de contraseñas en las cookies, lo que hace más fácil para los atacantes remotos obtener información sensible por la captura de tráfico (sniffing)de la red. • http://securityreason.com/securityalert/8385 http://www.coresecurity.com/content/multiples-vulnerabilities-manageengine-sdp http://www.securityfocus.com/archive/1/519652/100/0/threaded http://www.securityfocus.com/bid/49636 https://exchange.xforce.ibmcloud.com/vulnerabilities/69841 • CWE-310: Cryptographic Issues •
CVE-2011-1510
https://notcve.org/view.php?id=CVE-2011-1510
Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus (SDP) before 8012 allows remote attackers to inject arbitrary web script or HTML via the searchText parameter. Vulnerabilidad cross-site scripting (XSS) en SolutionSearch.do en ManageEngine ServiceDesk Plus (SDP) antes de v8012 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro searchText. • http://securityreason.com/securityalert/8385 http://www.coresecurity.com/content/multiples-vulnerabilities-manageengine-sdp http://www.securityfocus.com/archive/1/519652/100/0/threaded http://www.securityfocus.com/bid/49636 https://exchange.xforce.ibmcloud.com/vulnerabilities/69840 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •