Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the username is invalid.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ZOHO ManageEngine Password Manager Pro 安全漏洞
Vulnerability Description
ZOHO ManageEngine Password Manager Pro是美国卓豪(ZOHO)公司的一款密码管理器。 ZOHO ManageEngine Password Manager Pro 存在安全漏洞,该漏洞源于 Zoho ManageEngine Password Manager Pro 允许login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= 用户名枚举,因为只有当用户名无效时,响应(对失败的登录请求)才为空。
CVSS Information
N/A
Vulnerability Type
N/A