5
CVSSv2

CVE-2014-5445

Published: 04/12/2014 Updated: 15/07/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 up to and including 10.2 and IT360 10.3 allow remote attackers or remote authenticated users to read arbitrary files via a full pathname in the schFilePath parameter to the (1) CSVServlet or (2) CReportPDFServlet servlet.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zohocorp manageengine it360 10.3.0

zohocorp manageengine netflow analyzer

Exploits

>> Arbitrary file download in ManageEngine Netflow Analyzer and IT360 >> Discovered by Pedro Ribeiro (pedrib@gmailcom), Agile Information Security ========================================================================== Disclosure: 30/11/2014 / Last updated: 3/12/2014 >> Background on the affected product: "NetFlow Analyzer, a ...
ManageEngine Netflow Analyzer and IT360 suffer from an arbitrary file download vulnerability ...