Логотип exploitDog
bind:CVE-2018-12999
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-12999

Количество 2

Количество 2

nvd логотип

CVE-2018-12999

больше 7 лет назад

Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web server without login by sending a specially crafted request to the server with a computerName=../ substring to the /agenttrayicon URI.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-pf9m-66cq-7fx9

больше 3 лет назад

Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web server without login by sending a specially crafted request to the server with a computerName=../ substring to the /agenttrayicon URI.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-12999

Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web server without login by sending a specially crafted request to the server with a computerName=../ substring to the /agenttrayicon URI.

CVSS3: 7.5
10%
Низкий
больше 7 лет назад
github логотип
GHSA-pf9m-66cq-7fx9

Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web server without login by sending a specially crafted request to the server with a computerName=../ substring to the /agenttrayicon URI.

CVSS3: 7.5
10%
Низкий
больше 3 лет назад

Уязвимостей на страницу