First published: Thu Dec 04 2014(Updated: )
Directory traversal vulnerability in the FileCollector servlet in ZOHO ManageEngine OpManager 11.4, 11.3, and earlier allows remote attackers to write and execute arbitrary files via a .. (dot dot) in the FILENAME parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine OpManager MSP | <=11.3 | |
ManageEngine OpManager MSP | =11.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6035 has a high severity rating due to its potential for remote code execution.
To fix CVE-2014-6035, update to the latest version of ManageEngine OpManager that is not affected by the vulnerability.
CVE-2014-6035 affects ManageEngine OpManager versions 11.4, 11.3, and earlier.
Yes, CVE-2014-6035 can be exploited remotely by attackers exploiting the directory traversal vulnerability.
CVE-2014-6035 can allow attackers to write and execute arbitrary files, posing a significant security risk to users.