Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to execute arbitrary commands with SYSTEM privileges.
| Software | From | Fixed in |
|---|---|---|
| zohocorp / manageengine_servicedesk_plus | - | 11.2 |
| zohocorp / manageengine_servicedesk_plus | 11.2-build11201 | 11.2-build11201.x |
| zohocorp / manageengine_servicedesk_plus | 11.2-build11202 | 11.2-build11202.x |
| zohocorp / manageengine_servicedesk_plus | 11.2-build11203 | 11.2-build11203.x |
| zohocorp / manageengine_servicedesk_plus | 11.2-build11204 | 11.2-build11204.x |
| zohocorp / manageengine_servicedesk_plus | 11.2 | 11.2.x |