PT-2015-3608 · Manageengine · Manageengine Supportcenter Plus
Xistence
·
Publicado
2015-01-13
·
Atualizado
2017-09-08
·
CVE-2014-100002
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ManageEngine SupportCenter Plus versions 7.9 through 7917
Description
A directory traversal issue allows remote attackers to read arbitrary files by using a ..%2f (dot dot encoded slash) in the
attach parameter to "WorkOrder.do" in the file attachment for a new ticket.Recommendations
For ManageEngine SupportCenter Plus versions 7.9 through 7917, update to version 7917 or later to resolve the issue.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Manageengine Supportcenter Plus