Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-11512

The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name parameter for the download-snapshot URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.868
EPSS Ranking 99.4%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2017-11512


Contact Us

Shodan ® - All rights reserved