← Back

CVE-2014-7866

nvd nist
Published: Dec 10, 2014Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Multiple directory traversal vulnerabilities in ZOHO ManageEngine OpManager 8 (build 88xx) through 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allow remote attackers or remote authenticated users to write and execute arbitrary files via a .. (dot dot) in the (1) fileName parameter to the MigrateLEEData servlet or (2) zipFileName parameter in a downloadFileFromProbe operation to the MigrateCentralData servlet.

Affected (16)

3 products
Manageengine Social It Plus
Manageengine It360
Manageengine Opmanager
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.0
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Zohocorp
Version 10.3.0
Version 10.4
Configuration C
13 vulnerable

Timeline

No history available yet.