CVE-2015-1480

ZOHO ManageEngine ServiceDesk Plus <9.0 build 9031 - Info Disclosure

Title source: llm
STIX 2.1

Description

ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive ticket information via a (1) getTicketData action to servlet/AJaxServlet or a direct request to (2) swf/flashreport.swf, (3) reports/flash/details.jsp, or (4) reports/CreateReportTable.jsp.

Exploits (1)

exploitdb WRITEUP
by Rewterz - Research Group · textwebappsjsp
https://www.exploit-db.com/exploits/35904

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/show/osvdb/117499
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/35904
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72302
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/534538/100/0/threaded

Scores

EPSS 0.1823
EPSS Percentile 95.2%

Details

CWE
CWE-200
Status published
Products (1)
manageengine/servicedesk_plus < 9.0
Published Feb 04, 2015
Tracked Since Feb 18, 2026