
CVE-2011-2755 – ManageEngine ServiceDesk 8.0.0.12 - Database Disclosure
https://notcve.org/view.php?id=CVE-2011-2755
17 Jul 2011 — Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to read arbitrary files via unspecified vectors. Vulnerabilidad de salto de directorio en FileDownload.jsp en ManageEngine ServiceDesk Plus v8.0 con anterioridad a Build 8012 permite a atacantes remotos leer archivos arbitrarios a través de vectores no especificados. • https://www.exploit-db.com/exploits/17503 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2011-2756
https://notcve.org/view.php?id=CVE-2011-2756
17 Jul 2011 — FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to read files from a specific directory via unspecified vectors. En ManageEngine ServiceDesk Plus v8.0, el directorio FileDownload.jsp ,con anterioridad a Build 8012 no requiere autenticación, lo que permite a atacantes remotos leer archivos de un directorio específico a través de vectores no especificados. • http://www.kb.cert.org/vuls/id/543310 • CWE-287: Improper Authentication •

CVE-2011-2757 – ManageEngine ServiceDesk 8.0.0.12 - Database Disclosure
https://notcve.org/view.php?id=CVE-2011-2757
17 Jul 2011 — Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the FILENAME parameter. NOTE: this might overlap the US-CERT VU#543310 issue. Vulnerabilidad de salto de directorio en FileDownload.jsp en ManageEngine ServiceDesk Plus v8.0.0.12 y anteriores permite a atacantes remotos leer y ejecutar ficheros a su elección mediante secuencias .. (punto punto) en el parametro file. • https://www.exploit-db.com/exploits/17503 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2008-1299
https://notcve.org/view.php?id=CVE-2008-1299
12 Mar 2008 — Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Windows allows remote attackers to inject arbitrary web script or HTML via the searchText parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en SolutionSearch.do de ManageEngine ServiceDesk Plus 7.0.0 Build 7011 para Windows permite a atacantes remotos in... • http://secunia.com/advisories/29310 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •