ZOHO ManageEngine Password Manager Pro是美国卓豪(ZOHO)公司的一款密码管理器。 ZOHO ManageEngine Password Manager Pro 12101 之前版本和PAM360 5510之前版本存在安全漏洞,该漏洞源于容易受到未经身份验证的远程代码执行的攻击。(这也会影响 ManageEngine Access Manager Plus 4303之前版本的身份验证。)
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | ManageEngine PAM360, Password Manager Pro, and Access Manager Plus unauthenticated remote code execution vulnerability PoC-exploit | https://github.com/viniciuspereiras/CVE-2022-35405 | POC Details |
| 2 | Zoho ManageEngine Password Manager Pro, PAM 360, and Access Manager Plus are susceptible to unauthenticated remote code execution via XML-RPC. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-35405.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-34266 | 5.5 MEDIUM | Silicon Graphics LibTIFF 安全漏洞 |
| CVE-2022-36305 | Vesta Control Panel 跨站脚本漏洞 | |
| CVE-2022-2476 | WavPack 代码问题漏洞 | |
| CVE-2022-1921 | GStreamer 输入验证错误漏洞 | |
| CVE-2021-32504 | SICK FTMg 安全漏洞 | |
| CVE-2022-27579 | SICK Flexi Soft Designer 代码问题漏洞 | |
| CVE-2022-27580 | Safety 代码问题漏洞 | |
| CVE-2022-35912 | Grails 代码注入漏洞 | |
| CVE-2022-34001 | Unit4 ERP 代码问题漏洞 | |
| CVE-2022-34023 | Barangay Management System SQL注入漏洞 | |
| CVE-2022-34024 | Barangay Management System 代码问题漏洞 | |
| CVE-2022-27373 | phicomm Feixun fir302b A2 操作系统命令注入漏洞 | |
| CVE-2022-34025 | Vesta Control Panel 跨站脚本漏洞 | |
| CVE-2022-36304 | Vesta Control Panel 跨站脚本漏洞 | |
| CVE-2022-36303 | Vesta Control Panel 跨站脚本漏洞 | |
| CVE-2022-34535 | Digital Watchdog DW MEGApix IP 授权问题漏洞 | |
| CVE-2022-34534 | Digital Watchdog DW MEGApix IP 信息泄露漏洞 | |
| CVE-2022-34536 | Digital Watchdog DW MEGApix IP 授权问题漏洞 | |
| CVE-2022-34537 | Digital Watchdog DW MEGApix IP 跨站脚本漏洞 | |
| CVE-2022-34538 | Digital Watchdog DW MEGApix IP 操作系统命令注入漏洞 |
Showing top 20 of 29 CVEs. View all on vendor page → →
No comments yet