Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to read files from a specific directory via unspecified vectors.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ManageEngine ServiceDesk FileDownload.jsp授权问题漏洞
Vulnerability Description
ZOHO ManageEngine ServiceDesk是美国卓豪(ZOHO)公司的一套基于web的帮助台(HelpDesk)和资产管理软件。 ManageEngine ServiceDesk Plus Build 8012之前的8.0版本中的FileDownload.jsp不能请求认证。远程攻击者可借助未明向量从特定目录中读取文件。
CVSS Information
N/A
Vulnerability Type
N/A