VYPR

Servicedesk

Sign in to watch

by Manageengine

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-11512Hig0.557.50.83Nov 8, 2017The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name parameter for the download-snapshot URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.
CVE-2017-11511Hig0.497.50.04Nov 8, 2017The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filepath parameter for the download-file URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.