CVE-2011-2756

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
17/07/2011
Last modified:
11/04/2025

Description

FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to read files from a specific directory via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:manageengine:servicedesk_plus:8.0:*:*:*:*:*:*:*