6.5
CVSSv3

CVE-2019-8394

Published: 17/02/2019 Updated: 26/02/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 406
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

Zoho ManageEngine ServiceDesk Plus (SDP) prior to 10.0 build 10012 allows remote malicious users to upload arbitrary files via login page customization.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zohocorp manageengine servicedesk plus

Exploits

# Exploit Title: Zoho ManageEngine ServiceDesk Plus (SDP) before 100 build 10012 - arbitrary file upload # Date: 18-02-2019 # Exploit Author: Dao Duy Hung (duyhungattt@gmailcom) # Vendor Homepage: wwwmanageenginecom/products/service-desk/ # Software Link: wwwmanageenginecom/products/service-desk/downloadhtml?opDownload_indexb ...

Mailing Lists

Zoho ManageEngine ServiceDesk Plus (SDP) versions prior to 100 build 10012 suffer from an arbitrary file upload vulnerability ...

Github Repositories

CVEs enumerated by FireEye and that should be addressed to limit the effectiveness of leaked the Red Team tools CVE-2019-11510 – pre-auth arbitrary file reading from Pulse Secure SSL VPNs - CVSS 100 CVE-2020-1472 – Microsoft Active Directory escalation of privileges - CVSS 100 CVE-2018-13379 – pre-auth arbitrary file reading from Fortinet Fortigate SSL VPN

vFeed CVEs Vulnerability Indicators that should be addressed to limit the effectiveness of the Leaked FireEye Red Team tools CVE-2019-11510 – pre-auth arbitrary file reading from Pulse Secure SSL VPNs - CVSS 100 CVE-2020-1472 – Microsoft Active Directory escalation of privileges - CVSS 100 CVE-2018-13379 – pre-auth arbitrary file reading from Fortinet Forti