CVE-2011-2757: Path Traversal
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the FILENAME parameter. NOTE: this might overlap the US-CERT VU#543310 issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2757?
CVE-2011-2757 has a high severity level due to its potential to expose sensitive files to remote attackers.
How do I fix CVE-2011-2757?
To fix CVE-2011-2757, update ManageEngine ServiceDesk Plus to a version later than 8.0.0.12 or implement input validation to prevent directory traversal.
What systems are affected by CVE-2011-2757?
CVE-2011-2757 affects ManageEngine ServiceDesk Plus version 7.0.0 up to 8.0.0.12.
What type of attack is associated with CVE-2011-2757?
CVE-2011-2757 is associated with directory traversal attacks, which can allow unauthorized file access.
Is CVE-2011-2757 still a concern in current systems?
While CVE-2011-2757 primarily affects older versions of ManageEngine, unpatched systems using these versions remain vulnerable.