CVE-2014-100002: Path Traversal
Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the attach parameter to WorkOrder.do in the file attachment for a new ticket.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-100002?
CVE-2014-100002 is considered a medium severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2014-100002?
To fix CVE-2014-100002, upgrade ManageEngine SupportCenter Plus to version 7.9 build 7917 or later.
What types of attacks can exploit CVE-2014-100002?
CVE-2014-100002 can be exploited through directory traversal attacks, allowing attackers to read arbitrary files on the server.
Which versions of ManageEngine SupportCenter Plus are affected by CVE-2014-100002?
ManageEngine SupportCenter Plus versions up to and including 7.9 build 7916 are affected by CVE-2014-100002.
What specific parameter is vulnerable in CVE-2014-100002?
The 'attach' parameter in the WorkOrder.do file is vulnerable to directory traversal in CVE-2014-100002.