Логотип exploitDog
bind:CVE-2018-18980
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-18980

Количество 2

Количество 2

nvd логотип

CVE-2018-18980

больше 7 лет назад

An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local files to an arbitrary remote FTP server.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-g7qq-6w8p-g7fm

больше 3 лет назад

An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local files to an arbitrary remote FTP server.

CVSS3: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-18980

An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local files to an arbitrary remote FTP server.

CVSS3: 7.5
31%
Средний
больше 7 лет назад
github логотип
GHSA-g7qq-6w8p-g7fm

An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local files to an arbitrary remote FTP server.

CVSS3: 7.5
31%
Средний
больше 3 лет назад

Уязвимостей на страницу