CVE-2018-18715
https://notcve.org/view.php?id=CVE-2018-18715
Zoho ManageEngine OpManager 12.3 before 123219 has stored XSS. Zoho ManageEngine OpManager 12.3 antes de la build 123219 tiene Cross-Site Scripting (XSS) persistente. • http://packetstormsecurity.com/files/150124/Zoho-ManageEngine-OpManager-12.3-Cross-Site-Scripting.html http://seclists.org/fulldisclosure/2018/Nov/3 https://seclists.org/bugtraq/2018/Oct/60 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-18716
https://notcve.org/view.php?id=CVE-2018-18716
Zoho ManageEngine OpManager 12.3 before 123219 has a Self XSS Vulnerability. Zoho ManageEngine OpManager 12.3 antes de la build 123219 tiene una vulnerabilidad Self Cross-Site Scripting (XSS). • http://packetstormsecurity.com/files/150124/Zoho-ManageEngine-OpManager-12.3-Cross-Site-Scripting.html http://seclists.org/fulldisclosure/2018/Nov/6 https://seclists.org/bugtraq/2018/Oct/61 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-18475
https://notcve.org/view.php?id=CVE-2018-18475
Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload. Zoho ManageEngine OpManager en versiones anteriores a la 12.3 build 123214 permite la subida de archivos arbitrarios sin restricción. • http://packetstormsecurity.com/files/149878/Zoho-ManageEngine-OpManager-12.3-Arbitrary-File-Upload.html http://seclists.org/fulldisclosure/2018/Oct/42 • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2018-18262
https://notcve.org/view.php?id=CVE-2018-18262
Zoho ManageEngine OpManager 12.3 before build 123214 has XSS. Zoho ManageEngine OpManager 12.3 antes de la build 123214 tiene Cross-Site Scripting (XSS). • http://seclists.org/fulldisclosure/2018/Oct/34 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-17596 – ManageEngine AssetExplorer 6.2.0 Cross Site Scripting
https://notcve.org/view.php?id=CVE-2018-17596
In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ciName or assetName parameter. En Zoho ManageEngine AssetExplorer, se ha descubierto una vulnerabilidad de Cross-Site Scripting (XSS) persistente en la versión 6.2.0 mediante los parámetros ciName o assetName en /AssetDef.do. • http://packetstormsecurity.com/files/149597/ManageEngine-AssetExplorer-6.2.0-Cross-Site-Scripting.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •