CVE-2014-5446

Directory traversal vulnerability in the DisplayChartPDF servlet in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allows remote attackers and remote authenticated users to read arbitrary files via a .. (dot dot) in the filename parameter.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
zohocorpmanageengine_it360
10.3.0
zohocorpmanageengine_netflow_analyzer
8.6
zohocorpmanageengine_netflow_analyzer
9.0
zohocorpmanageengine_netflow_analyzer
9.1
zohocorpmanageengine_netflow_analyzer
9.5
zohocorpmanageengine_netflow_analyzer
9.6
zohocorpmanageengine_netflow_analyzer
9.7
zohocorpmanageengine_netflow_analyzer
9.8
zohocorpmanageengine_netflow_analyzer
9.8.5
zohocorpmanageengine_netflow_analyzer
9.8.6
zohocorpmanageengine_netflow_analyzer
9.8.7
zohocorpmanageengine_netflow_analyzer
9.9
zohocorpmanageengine_netflow_analyzer
10.0:beta
zohocorpmanageengine_netflow_analyzer
10.2
𝑥
= Vulnerable software versions