CVE-2014-5446

Directory traversal vulnerability in the DisplayChartPDF servlet in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allows remote attackers and remote authenticated users to read arbitrary files via a .. (dot dot) in the filename parameter.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zohocorp:manageengine_it360:10.3.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:8.6:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:9.0:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:9.1:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:9.5:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:9.6:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:9.7:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:9.8:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:9.8.5:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:9.8.6:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:9.8.7:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:9.9:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:10.0:beta:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:10.2:*:*:*:*:*:*:*

History

21 Nov 2024, 02:12

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/129336/ManageEngine-Netflow-Analyzer-IT360-File-Download.html - Exploit () http://packetstormsecurity.com/files/129336/ManageEngine-Netflow-Analyzer-IT360-File-Download.html - Exploit
References () http://seclists.org/fulldisclosure/2014/Dec/9 - Exploit () http://seclists.org/fulldisclosure/2014/Dec/9 - Exploit
References () http://www.securityfocus.com/archive/1/534122/100/0/threaded - () http://www.securityfocus.com/archive/1/534122/100/0/threaded -
References () http://www.securityfocus.com/archive/1/534141/100/0/threaded - () http://www.securityfocus.com/archive/1/534141/100/0/threaded -
References () http://www.securityfocus.com/bid/71404 - Exploit () http://www.securityfocus.com/bid/71404 - Exploit
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/99046 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/99046 -
References () https://raw.githubusercontent.com/pedrib/PoC/master/ManageEngine/me_netflow_it360_file_dl.txt - Exploit () https://raw.githubusercontent.com/pedrib/PoC/master/ManageEngine/me_netflow_it360_file_dl.txt - Exploit
References () https://support.zoho.com/portal/manageengine/helpcenter/articles/cve-2014-5445-cve-2014-5446-fix-for-arbitrary-file-download - Exploit, Patch () https://support.zoho.com/portal/manageengine/helpcenter/articles/cve-2014-5445-cve-2014-5446-fix-for-arbitrary-file-download - Exploit, Patch

Information

Published : 2014-12-04 17:59

Updated : 2024-11-21 02:12


NVD link : CVE-2014-5446

Mitre link : CVE-2014-5446

CVE.ORG link : CVE-2014-5446


JSON object : View

Products Affected

zohocorp

  • manageengine_netflow_analyzer
  • manageengine_it360
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')