Total vulnerabilities in the database
A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative interface via an HTTP request, a different vulnerability than CVE-2019-3905.
Software | From | Fixed in |
---|---|---|
zohocorp / manageengine_adselfservice_plus | 6.0 | 6.0.x |
zohocorp / manageengine_adselfservice_plus | 6.0-6000 | 6.0-6000.x |
zohocorp / manageengine_adselfservice_plus | 6.0-6001 | 6.0-6001.x |
zohocorp / manageengine_adselfservice_plus | 6.0-6002 | 6.0-6002.x |
zohocorp / manageengine_adselfservice_plus | 6.0-6009 | 6.0-6009.x |
zohocorp / manageengine_adselfservice_plus | 6.0-6012 | 6.0-6012.x |
zohocorp / manageengine_adselfservice_plus | 6.0-6013 | 6.0-6013.x |
zohocorp / manageengine_adselfservice_plus | 6.0-6003 | 6.0-6003.x |
zohocorp / manageengine_adselfservice_plus | 6.0-6004 | 6.0-6004.x |
zohocorp / manageengine_adselfservice_plus | 6.0-6005 | 6.0-6005.x |
zohocorp / manageengine_adselfservice_plus | 6.0-6006 | 6.0-6006.x |
zohocorp / manageengine_adselfservice_plus | 6.0-6007 | 6.0-6007.x |
zohocorp / manageengine_adselfservice_plus | 6.0-6008 | 6.0-6008.x |