VYPR

Servicedesk Plus

Sign in to watch

by Zohocorp

CVEs (4)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2016-4889Hig0.588.80.04Apr 14, 2017ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict access to unknown functions.
CVE-2016-4890Med0.355.30.03Apr 14, 2017ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive password information by leveraging access to a cookie.
CVE-2016-4888Med0.355.40.02Apr 14, 2017Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine ServiceDesk Plus before 9.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2015-14790.040.11Feb 4, 2015SQL injection vulnerability in reports/CreateReportTable.jsp in ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to execute arbitrary SQL commands via the site parameter.