PT-2015-6784 · Zoho · Zoho Manageengine Supportcenter Plus
Alain Homewood
·
Publicado
2015-06-30
·
Atualizado
2016-12-07
·
CVE-2015-5149
CVSS v2.0
5.5
Média
| Vetor | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Zoho ManageEngine SupportCenter Plus version 7.90
Description
A directory traversal issue exists, allowing remote authenticated users to write to arbitrary files. This is achieved by including a .. (dot dot) in the
component parameter in the Request component to "workorder/Attachment.jsp" API endpoint.Recommendations
For Zoho ManageEngine SupportCenter Plus version 7.90, consider restricting access to the "workorder/Attachment.jsp" endpoint until a patch is available. As a temporary workaround, avoid using the
component parameter in the Request component to minimize the risk of exploitation.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zoho Manageengine Supportcenter Plus