CVE-2014-6036
Directory traversal vulnerability in the multipartRequest servlet in ZOHO ManageEngine OpManager 11.3 and earlier, Social IT Plus 11.0, and IT360 10.3, 10.4, and earlier allows remote attackers or remote authenticated users to delete arbitrary files via…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 36.3%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Directory traversal vulnerability in the multipartRequest servlet in ZOHO ManageEngine OpManager 11.3 and earlier, Social IT Plus 11.0, and IT360 10.3, 10.4, and earlier allows remote attackers or remote authenticated users to delete arbitrary files via a .. (dot dot) in the fileName parameter.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
- EPSS
- 36.27% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- zohocorp/manageengine opmanager · zohocorp/manageengine it360 · zohocorp/manageengine social it plus
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2014/Sep/110Exploit
- https://raw.githubusercontent.com/pedrib/PoC/master/ManageEngine/me_opmanager_socialit_it360.txtExploit
- https://support.zoho.com/portal/manageengine/helpcenter/articles/servlet-vulnerability-fixPatch
- http://seclists.org/fulldisclosure/2014/Sep/110Exploit
- https://raw.githubusercontent.com/pedrib/PoC/master/ManageEngine/me_opmanager_socialit_it360.txtExploit
- https://support.zoho.com/portal/manageengine/helpcenter/articles/servlet-vulnerability-fixPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.