First published: Mon Sep 04 2017(Updated: )
Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section. Any user can upload files with any extensions. By uploading a PHP file to the server, an attacker can cause it to execute in the server context, as demonstrated by /itplus/FileStorage/302/shell.jsp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Firewall Analyzer | =12.2-12200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.