CVE-2014-7863
HIGHManageEngine Applications Manager <11.9/OpManager 8-11.5/IT360 <=10.5 - Unauthenticated Arbitrary File Read
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2014-7863.
Includes Metasploit module auxiliary/admin/http/manageengine_dir_listing.
AI-analyzed exploit summary The document details multiple vulnerabilities in ManageEngine products, specifically focusing on the FailOverHelperServlet. It includes technical descriptions of arbitrary file download, directory listing, and blind SQL injection vulnerabilities, along with affected versions and constraints.
Description
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and remote authenticated users to (1) read arbitrary files via the fileName parameter in a copyfile operation or (2) obtain sensitive information via a directory listing in a listdirectory operation to servlet/FailOverHelperServlet.
Exploits (3)
The document details multiple vulnerabilities in ManageEngine products, specifically focusing on the FailOverHelperServlet. It includes technical descriptions of arbitrary file download, directory listing, and blind SQL injection vulnerabilities, along with affected versions and constraints.
This Metasploit module exploits an unauthenticated directory listing vulnerability in ManageEngine products via the FailOverHelperServlet. It supports recursive directory traversal and includes authentication handling for IT360 targets.
This Metasploit module exploits an arbitrary file download vulnerability in ManageEngine products via the FailOverHelperServlet. It supports both authenticated and unauthenticated exploitation, depending on the target product, and includes functionality to handle IT360 authentication.
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N