CVE-2014-5446

Zohocorp Manageengine It360 - Path Traversal

Title source: rule
STIX 2.1

Description

Directory traversal vulnerability in the DisplayChartPDF servlet in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allows remote attackers and remote authenticated users to read arbitrary files via a .. (dot dot) in the filename parameter.

Exploits (1)

exploitdb WRITEUP
by Pedro Ribeiro · textwebappsmultiple
https://www.exploit-db.com/exploits/43895

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/99046
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/534141/100/0/threaded
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/71404
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/534122/100/0/threaded
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Dec/9

Scores

EPSS 0.6574
EPSS Percentile 98.5%

Details

CWE
CWE-22
Status published
Products (14)
zohocorp/manageengine_it360 10.3.0
zohocorp/manageengine_netflow_analyzer 8.6
zohocorp/manageengine_netflow_analyzer 9.0
zohocorp/manageengine_netflow_analyzer 9.1
zohocorp/manageengine_netflow_analyzer 9.5
zohocorp/manageengine_netflow_analyzer 9.6
zohocorp/manageengine_netflow_analyzer 9.7
zohocorp/manageengine_netflow_analyzer 9.8
zohocorp/manageengine_netflow_analyzer 9.8.5
zohocorp/manageengine_netflow_analyzer 9.8.6
... and 4 more
Published Dec 04, 2014
Tracked Since Feb 18, 2026