CVE-2014-7866

ZOHO ManageEngine OpManager 8-11.4 Path Traversal & Arbitrary File Write via Servlets

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2014-7866.

AI-analyzed exploit summary This is a detailed technical writeup describing multiple vulnerabilities in ManageEngine products, including CVE-2014-7866, which involves remote code execution via file upload. The document provides specific endpoints, payload formats, and affected versions, demonstrating a deep understanding of the vulnerabilities.

Description

Multiple directory traversal vulnerabilities in ZOHO ManageEngine OpManager 8 (build 88xx) through 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allow remote attackers or remote authenticated users to write and execute arbitrary files via a .. (dot dot) in the (1) fileName parameter to the MigrateLEEData servlet or (2) zipFileName parameter in a downloadFileFromProbe operation to the MigrateCentralData servlet.

Exploits (2)

exploitdb WRITEUP
webappsmultiple
https://www.exploit-db.com/exploits/43896

This is a detailed technical writeup describing multiple vulnerabilities in ManageEngine products, including CVE-2014-7866, which involves remote code execution via file upload. The document provides specific endpoints, payload formats, and affected versions, demonstrating a deep understanding of the vulnerabilities.

Classification
Writeup 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ManageEngine OpManager, Social IT Plus, IT360
No auth needed
Prerequisites: Network access to the target · Vulnerable version of ManageEngine software
devstral-2 · analyzed Feb 19, 2026 Full analysis →
exploitdb WRITEUP
webappsjsp
https://www.exploit-db.com/exploits/35209

This is a detailed technical writeup describing multiple vulnerabilities in ManageEngine OpManager, Social IT Plus, and IT360, including remote code execution via file upload (CVE-2014-7866) and blind SQL injection (CVE-2014-7868). It provides specific exploit paths, affected versions, and mitigation steps.

Classification
Writeup 100%
Attack Type
Rce | Sqli
Complexity
Moderate
Reliability
Reliable
Target: ManageEngine OpManager (v8 build 88XX to 11.4), IT360 (10.3/10.4), Social IT (11.0)
No auth needed
Prerequisites: Network access to the target application · No authentication required for OpManager and Social IT
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Scores

EPSS 0.7976
EPSS Percentile 99.6%

Details

CWE
CWE-22
Status published
Products (16)
zohocorp/manageengine_it360 10.3.0
zohocorp/manageengine_it360 10.4
zohocorp/manageengine_opmanager 8.8
zohocorp/manageengine_opmanager 9.0
zohocorp/manageengine_opmanager 9.1
zohocorp/manageengine_opmanager 9.2
zohocorp/manageengine_opmanager 9.4
zohocorp/manageengine_opmanager 10.0
zohocorp/manageengine_opmanager 10.1
zohocorp/manageengine_opmanager 10.2
... and 6 more
Published Dec 10, 2014
Tracked Since Feb 18, 2026