Posted by Pedro Ribeiro on Jan 05
Hi,
This is part 11 of the ManageOwnage series. For previous parts, see [1].
This time we have two remote code execution via file upload (and
directory traversal) on several ManageEngine products – Service Desk
Plus, Asset Explorer, Support Center and IT360.
The first vulnerability can only be exploited by an authenticated
user, but it can be a low privileged guest (which is a default account
present in almost all installations). This…