Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section

2018-12-21 Thread Murat Aydemir
- 20/11/18 Vulnerability discovered 20/11/18 Vendor contacted 20/12/2018 OPManager replay that they fixed V. CREDIT - Murat Aydemir from Biznet Bilisim A.S. VI. DESCRIPTION - ManageEngine OPManager product(version 12.3

Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section

2018-12-21 Thread Murat Aydemir
- 20/11/18 Vulnerability discovered 20/11/18 Vendor contacted 20/12/2018 OPManager replay that they fixed V. CREDIT - Murat Aydemir from Biznet Bilisim A.S. VI. DESCRIPTION - ManageEngine OPManager product(version 12.3) was vulnerable to SQL

Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API

2018-12-17 Thread Murat Aydemir
- 20/11/18 Vulnerability discovered 20/11/18 Vendor contacted 17/12/2018 OPManager replay that they fixed V. CREDIT - Murat Aydemir from Biznet Bilisim A.S. VI. DESCRIPTION - ManageEngine OPManager product(version 12.3) was vulnerable to SQL

Zoho ManageEngine OpManager 12.3 before Build 123237 has XSS via the domainController API.

2018-12-11 Thread Murat Aydemir
- 20/11/18 Vulnerability discovered 20/11/18 Vendor contacted 06/12/2018 OPManager replay that they fixed V. CREDIT - Murat Aydemir from Biznet Bilisim A.S. VI. DESCRIPTION - ManageEngine OPManager product(version 12.3) was vulnerable to stored xss

Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API.

2018-11-19 Thread Murat Aydemir
- 17/10/18 Vulnerability discovered 18/10/18 Vendor contacted 18/11/2018 OPManager replay that they fixed V. CREDIT - Murat Aydemir from Biznet Bilisim A.S. VI. DESCRIPTION - ManageEngine OPManager product(version 12.3) was vulnerable to stored xss

Zoho ManageEngine OpManager 12.3 allows Unrestricted Arbitrary File Upload

2018-10-23 Thread Murat Aydemir
Vulnerability discovered 19/09/18 Vendor contacted 16/10/2018 OPManager replay that they fixed V. CREDIT - Murat Aydemir and Hakan Bayir at Biznet Bilisim A.S. VI. DESCRIPTION - ManageEngine OPManager product(version 12.3) was allows to arbitrary

OPManager SQL Injection Vulnerability

2018-09-20 Thread Murat Aydemir
13/09/18 Vendor contacted 19/09/2018 OPManager replay that they fixed V. CREDIT - Murat Aydemir from Biznet Bilisim A.S. VI. DESCRIPTION - ManageEngine OPManager product(version 12.3) was vulnerable to sql injection attack. A successfully exploit