5
CVSSv2

CVE-2014-5446

Published: 04/12/2014 Updated: 15/07/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in the DisplayChartPDF servlet in ZOHO ManageEngine Netflow Analyzer 8.6 up to and including 10.2 and IT360 10.3 allows remote attackers and remote authenticated users to read arbitrary files via a .. (dot dot) in the filename parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zohocorp manageengine it360 10.3.0

zohocorp manageengine netflow analyzer 9.1

zohocorp manageengine netflow analyzer 9.5

zohocorp manageengine netflow analyzer 9.9

zohocorp manageengine netflow analyzer 10.0

zohocorp manageengine netflow analyzer 9.6

zohocorp manageengine netflow analyzer 9.7

zohocorp manageengine netflow analyzer 10.2

zohocorp manageengine netflow analyzer 9.8

zohocorp manageengine netflow analyzer 9.8.5

zohocorp manageengine netflow analyzer 8.6

zohocorp manageengine netflow analyzer 9.0

zohocorp manageengine netflow analyzer 9.8.6

zohocorp manageengine netflow analyzer 9.8.7

Exploits

>> Arbitrary file download in ManageEngine Netflow Analyzer and IT360 >> Discovered by Pedro Ribeiro (pedrib@gmailcom), Agile Information Security ========================================================================== Disclosure: 30/11/2014 / Last updated: 3/12/2014 >> Background on the affected product: "NetFlow Analyzer, a ...
ManageEngine Netflow Analyzer and IT360 suffer from an arbitrary file download vulnerability ...