CVE-2014-7866: Path Traversal
Multiple directory traversal vulnerabilities in ZOHO ManageEngine OpManager 8 (build 88xx) through 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allow remote attackers or remote authenticated users to write and execute arbitrary files via a .. (dot dot) in the (1) fileName parameter to the MigrateLEEData servlet or (2) zipFileName parameter in a downloadFileFromProbe operation to the MigrateCentralData servlet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7866?
CVE-2014-7866 is classified as a medium severity vulnerability that allows directory traversal.
How do I fix CVE-2014-7866?
To fix CVE-2014-7866, update your ZOHO ManageEngine OpManager, IT360, or Social IT Plus to the latest version available that addresses this vulnerability.
What software versions are affected by CVE-2014-7866?
CVE-2014-7866 affects ZOHO ManageEngine OpManager versions 8 (build 88xx) through 11.4, IT360 versions 10.3 and 10.4, and Social IT Plus version 11.0.
Can CVE-2014-7866 be exploited remotely?
Yes, CVE-2014-7866 can be exploited by remote attackers or remote authenticated users to write and execute arbitrary files.
What type of vulnerability is CVE-2014-7866?
CVE-2014-7866 is categorized as a directory traversal vulnerability that allows unauthorized file access.