Show filters
56 Total Results
Displaying 51-56 of 56
Sort by:
Attacker Value
Unknown

CVE-2019-10273

Disclosure Date: April 04, 2019 (last updated November 27, 2024)
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify any active account.
0
Attacker Value
Unknown

CVE-2017-9362

Disclosure Date: March 25, 2019 (last updated November 27, 2024)
ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.
0
Attacker Value
Unknown

CVE-2017-9376

Disclosure Date: March 25, 2019 (last updated November 27, 2024)
ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do.
0
Attacker Value
Unknown

CVE-2019-8395

Disclosure Date: February 17, 2019 (last updated November 27, 2024)
An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment to a request.
0
Attacker Value
Unknown

CVE-2018-7248

Disclosure Date: May 11, 2018 (last updated November 08, 2023)
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the username to an API endpoint. The endpoint will return the user's logon domain if the accounts exists, or 'null' if it does not.
Attacker Value
Unknown

CVE-2018-5799

Disclosure Date: March 30, 2018 (last updated November 26, 2024)
In Zoho ManageEngine ServiceDesk Plus before 9403, an XSS issue allows an attacker to run arbitrary JavaScript via a /api/request/?OPERATION_NAME= URI, aka SD-69139.
0