RULE(RULE ID:316472)

Rule General Information
Release Date: 2015-11-25
Rule Name: FILE-OTHER ManageEngine ServiceDesk File Upload Directory Traversal (ZDI-15-396)
Severity:
CVE ID:
Rule Protection Details
Description: A directory traversal vulnerability exists in ManageEngine ServiceDesk. The specific flaw occurs in the way the vulnerable product extracts uploaded ZIP files.
Impact: Information disclosure
Affected OS: Windows, Other Unix, FreeBSD, Linux
Reference: ZeroDayInitiative:ZDI-15-396
Solutions
Update vendor's patch.