CVE-2020-21642
15.08.2022, 20:15
Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code.
Vendor | Product | Version |
---|---|---|
zohocorp | manageengine_analytics_plus | 2.9:build2900 |
zohocorp | manageengine_analytics_plus | 2.9:build2901 |
zohocorp | manageengine_analytics_plus | 2.9:build2902 |
zohocorp | manageengine_analytics_plus | 2.9:build2903 |
zohocorp | manageengine_analytics_plus | 2.9:build2904 |
zohocorp | manageengine_analytics_plus | 2.9:build2905 |
zohocorp | manageengine_analytics_plus | 2.9:build2906 |
zohocorp | manageengine_analytics_plus | 2.9:build2907 |
zohocorp | manageengine_analytics_plus | 3.0:build3000 |
zohocorp | manageengine_analytics_plus | 3.0:build3010 |
zohocorp | manageengine_analytics_plus | 3.0:build3020 |
zohocorp | manageengine_analytics_plus | 3.0:build3030 |
zohocorp | manageengine_analytics_plus | 3.0:build3040 |
zohocorp | manageengine_analytics_plus | 3.0:build3050 |
zohocorp | manageengine_analytics_plus | 3.1:build3100 |
zohocorp | manageengine_analytics_plus | 3.1:build3110 |
zohocorp | manageengine_analytics_plus | 3.1:build3120 |
zohocorp | manageengine_analytics_plus | 3.1:build3130 |
zohocorp | manageengine_analytics_plus | 3.1:build3140 |
zohocorp | manageengine_analytics_plus | 3.2:build3200 |
zohocorp | manageengine_analytics_plus | 3.2:build3250 |
zohocorp | manageengine_analytics_plus | 3.3:build3300 |
zohocorp | manageengine_analytics_plus | 3.3:build3310 |
zohocorp | manageengine_analytics_plus | 3.4:build3400 |
zohocorp | manageengine_analytics_plus | 3.4:build3450 |
zohocorp | manageengine_analytics_plus | 3.5:build3500 |
zohocorp | manageengine_analytics_plus | 3.6:build3600 |
zohocorp | manageengine_analytics_plus | 3.7:build3700 |
zohocorp | manageengine_analytics_plus | 3.8:build3800 |
zohocorp | manageengine_analytics_plus | 3.9:build3900 |
zohocorp | manageengine_analytics_plus | 3.9:build3950 |
zohocorp | manageengine_analytics_plus | 4.0:build4000 |
zohocorp | manageengine_analytics_plus | 4.1:build4100 |
zohocorp | manageengine_analytics_plus | 4.1:build4150 |
zohocorp | manageengine_analytics_plus | 4.2:build4200 |
zohocorp | manageengine_analytics_plus | 4.2:build4250 |
zohocorp | manageengine_analytics_plus | 4.2:build4260 |
zohocorp | manageengine_analytics_plus | 4.2:build4270 |
zohocorp | manageengine_analytics_plus | 4.2:build4280 |
zohocorp | manageengine_analytics_plus | 4.3:build4300 |
zohocorp | manageengine_analytics_plus | 4.3:build4310 |
𝑥
= Vulnerable software versions