CVE-2015-5149

Zohocorp Manageengine Supportcenter Plus - Path Traversal

Title source: rule
STIX 2.1

Description

Directory traversal vulnerability in Zoho ManageEngine SupportCenter Plus 7.90 allows remote authenticated users to write to arbitrary files via a .. (dot dot) in the component parameter in the Request component to workorder/Attachment.jsp.

Exploits (1)

exploitdb WRITEUP
by Vulnerability-Lab · textwebappsmultiple
https://www.exploit-db.com/exploits/37322

References (4)

Core 4

Scores

EPSS 0.4246
EPSS Percentile 97.5%

Details

CWE
CWE-22
Status published
Products (1)
zohocorp/manageengine_supportcenter_plus 7.90
Published Jun 30, 2015
Tracked Since Feb 18, 2026