CVE-2014-6037

ManageEngine EventLog Analyzer 9.0/8.2 - Remote Code Execution via ZIP Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2014-6037. PoCs published by Metasploit, Hans-Martin Muench, h0ng10, including Metasploit module exploits/multi/http/eventlog_file_upload.

AI-analyzed exploit summary This Metasploit module exploits an unauthenticated file upload vulnerability in ManageEngine Eventlog Analyzer via the agentUpload servlet, allowing remote code execution through insecure handling of ZIP file contents. It supports multiple versions (7.0-9.9) and platforms (Windows/Linux/Java).

Description

Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 allows remote attackers to execute arbitrary code by uploading a ZIP file which contains an executable file with .. (dot dot) sequences in its name, then accessing the executable via a direct request to the file under the web root. Fixed in Build 11072.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/34670

This Metasploit module exploits an unauthenticated file upload vulnerability in ManageEngine Eventlog Analyzer via the agentUpload servlet, allowing remote code execution through insecure handling of ZIP file contents. It supports multiple versions (7.0-9.9) and platforms (Windows/Linux/Java).

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ManageEngine Eventlog Analyzer v7.0 - v9.9 b9002
No auth needed
Prerequisites: Network access to target · ManageEngine Eventlog Analyzer running on port 8400
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC
by Hans-Martin Muench · textwebappsjsp
https://www.exploit-db.com/exploits/34519

This exploit demonstrates an unauthenticated remote code execution vulnerability in ManageEngine EventLog Analyzer via a malicious ZIP file upload to the 'agentUpload' servlet, allowing arbitrary file placement in the web root. It also highlights an authorization bypass issue enabling low-privileged users to access the database browser.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: ManageEngine EventLog Analyzer 9.9 (Build 9002) and earlier
No auth needed
Prerequisites: Network access to the target server · Ability to craft a malicious ZIP file using evilarc
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by h0ng10 · rubypocjava
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/eventlog_file_upload.rb

This Metasploit module exploits an unauthenticated file upload vulnerability in ManageEngine Eventlog Analyzer (CVE-2014-6037) by uploading a malicious ZIP file containing a JSP payload, leading to remote code execution. It supports multiple versions and platforms, including Java, Windows, and Linux targets.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ManageEngine Eventlog Analyzer v7.0 - v9.9 b9002
No auth needed
Prerequisites: Network access to the target's HTTP service (port 8400 by default) · Vulnerable version of ManageEngine Eventlog Analyzer
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/34519
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Aug/86
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Sep/1
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Sep/19
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/69482
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Sep/20
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/show/osvdb/110642

Scores

EPSS 0.8418
EPSS Percentile 99.7%

Details

CWE
CWE-22
Status published
Products (2)
zohocorp/manageengine_eventlog_analyzer 8.2 8020
zohocorp/manageengine_eventlog_analyzer 9.0 9002
Published Oct 26, 2014
Tracked Since Feb 18, 2026