Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to execute arbitrary commands with SYSTEM privileges.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Manageengine_servicedesk_plus | Zohocorp | * | 11.2 (excluding) |
Manageengine_servicedesk_plus | Zohocorp | 11.2 (including) | 11.2 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.2-build11201 (including) | 11.2-build11201 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.2-build11202 (including) | 11.2-build11202 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.2-build11203 (including) | 11.2-build11203 (including) |
Manageengine_servicedesk_plus | Zohocorp | 11.2-build11204 (including) | 11.2-build11204 (including) |