CVE-2014-6036

EUVD-2014-5924
Directory traversal vulnerability in the multipartRequest servlet in ZOHO ManageEngine OpManager 11.3 and earlier, Social IT Plus 11.0, and IT360 10.3, 10.4, and earlier allows remote attackers or remote authenticated users to delete arbitrary files via a .. (dot dot) in the fileName parameter.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.4 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
Affected Products (NVD)
VendorProductVersion
zohocorpmanageengine_opmanager
𝑥
≤ 11.3
zohocorpmanageengine_it360
𝑥
≤ 10.4
zohocorpmanageengine_it360
10.3.0
zohocorpmanageengine_social_it_plus
11.0
𝑥
= Vulnerable software versions