← Back

CVE-2014-6036

nvd nist
Published: Dec 4, 2014Modified: May 6, 2026

JSON object

Loading...
6.4
Vector
AV:N/AC:L/Au:N/C:N/I:P/A:P
Exploitability: 10.0 / Impact: 4.9
Source: NVD

Description

Directory traversal vulnerability in the multipartRequest servlet in ZOHO ManageEngine OpManager 11.3 and earlier, Social IT Plus 11.0, and IT360 10.3, 10.4, and earlier allows remote attackers or remote authenticated users to delete arbitrary files via a .. (dot dot) in the fileName parameter.

Affected (4)

3 products
Manageengine Opmanager
Manageengine It360
Manageengine Social It Plus
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 11.3
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Zohocorp
Up to 10.4
Version 10.3.0
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.0

Timeline

No history available yet.