Zoho ManageEngine NetFlow Analyzer Professional CVE-2019-8925 Directory Traversal Vulnerability
BID:108553
Info
Zoho ManageEngine NetFlow Analyzer Professional CVE-2019-8925 Directory Traversal Vulnerability
| Bugtraq ID: | 108553 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-8925 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 19 2019 12:00AM |
| Updated: | Feb 19 2019 12:00AM |
| Credit: | Rafael Pedrero. |
| Vulnerable: |
Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2 |
| Not Vulnerable: |
Zoho ManageEngine Netflow Analyzer Professional 12.3.323 |
Exploit / POC
Zoho ManageEngine NetFlow Analyzer Professional CVE-2019-8925 Directory Traversal Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
Zoho ManageEngine NetFlow Analyzer Professional CVE-2019-8925 Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Zoho ManageEngine NetFlow Analyzer Professional CVE-2019-8925 Directory Traversal Vulnerability
References:
References:
- [CVE-2019-8925 to CVE-2019-8929] Path traversal and Cross Site Scripting in Zoho (ZOHO Corporation)
- Zoho ManageEngine NetFlow Analyzer Homepage (ZOHO Corporation)
- Vendor advisory (ZOHO Corporation)