VendorsZoho Corpservicedesk_plusany version
Vulnerabilities

Zoho Corp ZohoCorp ManageEngine ServiceDesk Plus any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2016-4889
ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict access to unknown functions.
Published 2017-04-14 · Modified
8.8EPSS 0.027
CVE-2015-1479
SQL injection vulnerability in reports/CreateReportTable.jsp in ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to execute arbitrary SQL commands via the site parameter.
Published 2015-02-04 · Modified
6.51 PoCEPSS 0.039
CVE-2016-4888
Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine ServiceDesk Plus before 9.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2017-04-14 · Modified
5.4EPSS 0.019
CVE-2016-4890
ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive password information by leveraging access to a cookie.
Published 2017-04-14 · Modified
5.3EPSS 0.035