CVE-2014-6035: Path Traversal
Published Dec 4, 2014
·Updated
Directory traversal vulnerability in the FileCollector servlet in ZOHO ManageEngine OpManager 11.4, 11.3, and earlier allows remote attackers to write and execute arbitrary files via a .. (dot dot) in the FILENAME parameter.
Affected Software
2 affected components
ZohoCorp ManageEngine OpManager<=11.3
ZohoCorp ManageEngine OpManager=11.4
Remediation
Event History
Dec 4, 2014
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6035?
CVE-2014-6035 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2014-6035?
To fix CVE-2014-6035, update to the latest version of ManageEngine OpManager that is not affected by the vulnerability.
3
What versions of ManageEngine OpManager are affected by CVE-2014-6035?
CVE-2014-6035 affects ManageEngine OpManager versions 11.4, 11.3, and earlier.
4
Can CVE-2014-6035 be exploited remotely?
Yes, CVE-2014-6035 can be exploited remotely by attackers exploiting the directory traversal vulnerability.
5
What impact does CVE-2014-6035 have on users?
CVE-2014-6035 can allow attackers to write and execute arbitrary files, posing a significant security risk to users.