Show filters
56 Total Results
Displaying 51-56 of 56
Sort by:
Attacker Value
Unknown
CVE-2019-10273
Disclosure Date: April 04, 2019 (last updated November 27, 2024)
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify any active account.
0
Attacker Value
Unknown
CVE-2017-9362
Disclosure Date: March 25, 2019 (last updated November 27, 2024)
ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.
0
Attacker Value
Unknown
CVE-2017-9376
Disclosure Date: March 25, 2019 (last updated November 27, 2024)
ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do.
0
Attacker Value
Unknown
CVE-2019-8395
Disclosure Date: February 17, 2019 (last updated November 27, 2024)
An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment to a request.
0
Attacker Value
Unknown
CVE-2018-7248
Disclosure Date: May 11, 2018 (last updated November 08, 2023)
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the username to an API endpoint. The endpoint will return the user's logon domain if the accounts exists, or 'null' if it does not.
0
Attacker Value
Unknown
CVE-2018-5799
Disclosure Date: March 30, 2018 (last updated November 26, 2024)
In Zoho ManageEngine ServiceDesk Plus before 9403, an XSS issue allows an attacker to run arbitrary JavaScript via a /api/request/?OPERATION_NAME= URI, aka SD-69139.
0