Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/46413/ | exploit vdb entry third party advisory |
http://www.securityfocus.com/bid/107129 | vdb entry third party advisory |
https://www.manageengine.com/products/service-desk/readme.html | release notes vendor advisory |