CVE-2011-2756
ManageEngine ServiceDesk Plus 8.0 - Unauthenticated Arbitrary File Read via FileDownload.jsp
Title source: llmDescription
FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to read files from a specific directory via unspecified vectors.
References (1)
Core 1
Core References
US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/543310
Scores
EPSS
0.0198
EPSS Percentile
78.0%
Details
CWE
CWE-287
Status
published
Products (1)
manageengine/servicedesk_plus
8.0
Published
Jul 17, 2011
Tracked Since
Feb 18, 2026