First published: Wed Dec 10 2014(Updated: )
Multiple directory traversal vulnerabilities in ZOHO ManageEngine OpManager 8 (build 88xx) through 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allow remote attackers or remote authenticated users to write and execute arbitrary files via a .. (dot dot) in the (1) fileName parameter to the MigrateLEEData servlet or (2) zipFileName parameter in a downloadFileFromProbe operation to the MigrateCentralData servlet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Social It Plus | =11.0 | |
Zohocorp Manageengine It360 | =10.3.0 | |
Zohocorp Manageengine It360 | =10.4 | |
Zohocorp ManageEngine OpManager | =8.8 | |
Zohocorp ManageEngine OpManager | =9.0 | |
Zohocorp ManageEngine OpManager | =9.1 | |
Zohocorp ManageEngine OpManager | =9.2 | |
Zohocorp ManageEngine OpManager | =9.4 | |
Zohocorp ManageEngine OpManager | =10.0 | |
Zohocorp ManageEngine OpManager | =10.1 | |
Zohocorp ManageEngine OpManager | =10.2 | |
Zohocorp ManageEngine OpManager | =11.0 | |
Zohocorp ManageEngine OpManager | =11.1 | |
Zohocorp ManageEngine OpManager | =11.2 | |
Zohocorp ManageEngine OpManager | =11.3 | |
Zohocorp ManageEngine OpManager | =11.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.