Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/46413/ | third party advisory exploit vdb entry |
http://www.securityfocus.com/bid/107129 | vdb entry third party advisory |
https://www.manageengine.com/products/service-desk/readme.html | vendor advisory release notes |