Record summary

CVE-2015-1480 has a selected CVSS score of 4.0; EIP currently links 1 catalogued exploit.

Description

ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive ticket information via a (1) getTicketData action to servlet/AJaxServlet or a direct request to (2) swf/flashreport.swf, (3) reports/flash/details.jsp, or (4) reports/CreateReportTable.jsp.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBManageEngine ServiceDesk Plus 9.0 < Build 9031 - User Privileges ManagementExploitDB exploitby Rewterz - Research GroupNot analyzed1 file
ExploitDB

PoC details

References

8