Search Results (Refine Search)
- CPE Product Version: cpe:/a:zohocorp:manageengine_eventlog_analyzer:9.0:9000
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2014-4930 |
Multiple cross-site scripting (XSS) vulnerabilities in event/index2.do in ManageEngine EventLog Analyzer before 9.0 build 9002 allow remote attackers to inject arbitrary web script or HTML via the (1) width, (2) height, (3) url, (4) helpP, (5) tab, (6) module, (7) completeData, (8) RBBNAME, (9) TC, (10) rtype, (11) eventCriteria, (12) q, (13) flushCache, or (14) product parameter. Fixed in Build 11072. Published: August 29, 2014; 9:55:04 AM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
CVE-2014-5103 |
Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine EventLog Analyzer 9 build 9000 allows remote attackers to inject arbitrary web script or HTML via the j_username parameter to event/j_security_check. Fixed in Version 10 Build 10000. Published: July 25, 2014; 3:55:07 PM -0400 |
V3.x:(not available) V2.0: 4.3 MEDIUM |