First published: Tue Jun 30 2015(Updated: )
Directory traversal vulnerability in Zoho ManageEngine SupportCenter Plus 7.90 allows remote authenticated users to write to arbitrary files via a .. (dot dot) in the component parameter in the Request component to workorder/Attachment.jsp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine SupportCenter Plus | =7.90 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5149 has a medium severity rating due to its potential for unauthorized file access.
To fix CVE-2015-5149, update Zoho ManageEngine SupportCenter Plus to the latest version that addresses this vulnerability.
CVE-2015-5149 affects remote authenticated users of Zoho ManageEngine SupportCenter Plus version 7.90.
The exploitation of CVE-2015-5149 can lead to unauthorized remote file writes, compromising the integrity of the system.
No, CVE-2015-5149 requires remote authenticated access to be exploited.