CVE-2014-100002
Zohocorp Manageengine Supportcenter Plus < 7.9 - Path Traversal
Title source: ruleDescription
Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the attach parameter to WorkOrder.do in the file attachment for a new ticket.
Exploits (2)
Scores
EPSS
0.7887
EPSS Percentile
99.1%
Details
CWE
CWE-22
Status
published
Products (1)
zohocorp/manageengine_supportcenter_plus
< 7.9
Published
Jan 13, 2015
Tracked Since
Feb 18, 2026