CVE-2015-1479

ZOHO ManageEngine SDP <9.0.9031 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in reports/CreateReportTable.jsp in ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to execute arbitrary SQL commands via the site parameter.

Exploits (1)

exploitdb WORKING POC
by Muhammad Ahmed Siddiqui · textwebappsjsp
https://www.exploit-db.com/exploits/35890

Scores

EPSS 0.1056
EPSS Percentile 93.3%

Details

CWE
CWE-89
Status published
Products (1)
zohocorp/servicedesk_plus < 9.0
Published Feb 04, 2015
Tracked Since Feb 18, 2026