CVE-2014-5446
04.12.2014, 17:59
Directory traversal vulnerability in the DisplayChartPDF servlet in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allows remote attackers and remote authenticated users to read arbitrary files via a .. (dot dot) in the filename parameter.
Vendor | Product | Version |
---|---|---|
zohocorp | manageengine_it360 | 10.3.0 |
zohocorp | manageengine_netflow_analyzer | 8.6 |
zohocorp | manageengine_netflow_analyzer | 9.0 |
zohocorp | manageengine_netflow_analyzer | 9.1 |
zohocorp | manageengine_netflow_analyzer | 9.5 |
zohocorp | manageengine_netflow_analyzer | 9.6 |
zohocorp | manageengine_netflow_analyzer | 9.7 |
zohocorp | manageengine_netflow_analyzer | 9.8 |
zohocorp | manageengine_netflow_analyzer | 9.8.5 |
zohocorp | manageengine_netflow_analyzer | 9.8.6 |
zohocorp | manageengine_netflow_analyzer | 9.8.7 |
zohocorp | manageengine_netflow_analyzer | 9.9 |
zohocorp | manageengine_netflow_analyzer | 10.0:beta |
zohocorp | manageengine_netflow_analyzer | 10.2 |
𝑥
= Vulnerable software versions
References