Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section. Any user can upload files with any extensions. By uploading a PHP file to the server, an attacker can cause it to execute in the server context, as demonstrated by /itplus/FileStorage/302/shell.jsp.
References
Link | Resource |
---|---|
https://blogs.securiteam.com/index.php/archives/3228 | Exploit Patch Third Party Advisory |
https://pitstop.manageengine.com/portal/kb/articles/latest-consolidated-patch | Patch Vendor Advisory |
https://blogs.securiteam.com/index.php/archives/3228 | Exploit Patch Third Party Advisory |
https://pitstop.manageengine.com/portal/kb/articles/latest-consolidated-patch | Patch Vendor Advisory |
Configurations
History
21 Nov 2024, 03:12
Type | Values Removed | Values Added |
---|---|---|
References | () https://blogs.securiteam.com/index.php/archives/3228 - Exploit, Patch, Third Party Advisory | |
References | () https://pitstop.manageengine.com/portal/kb/articles/latest-consolidated-patch - Patch, Vendor Advisory |
Information
Published : 2017-09-04 20:29
Updated : 2024-11-21 03:12
NVD link : CVE-2017-14123
Mitre link : CVE-2017-14123
CVE.ORG link : CVE-2017-14123
JSON object : View
Products Affected
zohocorp
- manageengine_firewall_analyzer
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type