Vulnerabilities
Vulnerable Software
Manageengine:  >> Servicedesk  Security Vulnerabilities
The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filepath parameter for the download-file URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.
CVSS Score
7.5
EPSS Score
0.041
Published
2017-11-08
The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name parameter for the download-snapshot URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.
CVSS Score
7.5
EPSS Score
0.868
Published
2017-11-08


Contact Us

Shodan ® - All rights reserved