Description
Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remote attackers to delete arbitrary files via a .. (dot dot) in a filename.
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-14-421/
Vendor Advisory x_refsource_confirm
http://www.manageengine.com/products/passwordmanagerpro/release-notes.html
Scores
EPSS
0.0163
EPSS Percentile
73.4%
Details
CWE
CWE-22
Status
published
Products (1)
manageengine/password_manager_pro
< 7.1
Published
Dec 16, 2014
Tracked Since
Feb 18, 2026