Multiple ManageEngine Products CVE-2014-6034 Arbitrary File Upload Vulnerability
BID:70167
Info
Multiple ManageEngine Products CVE-2014-6034 Arbitrary File Upload Vulnerability
| Bugtraq ID: | 70167 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-6034 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 27 2014 12:00AM |
| Updated: | May 12 2015 07:35PM |
| Credit: | Pedro Ribeiro, Agile Information Security |
| Vulnerable: |
ZOHO Corporation ManageEngine Social IT Plus 11.0 ZOHO Corporation ManageEngine OpManager 8.8 ZOHO Corporation ManageEngine OpManager 11.3 ZOHO Corporation ManageEngine OpManager 10.0 ZOHO Corporation ManageEngine IT360 10.4 ZOHO Corporation ManageEngine IT360 10.0 |
| Not Vulnerable: |
ZOHO Corporation ManageEngine Social IT Plus 11.0 build 11300 ZOHO Corporation ManageEngine OpManager 11.3 build 11300 ZOHO Corporation ManageEngine IT360 10.4 build 11300 |
Discussion
Multiple ManageEngine Products CVE-2014-6034 Arbitrary File Upload Vulnerability
Multiple ManageEngine Products are prone to an arbitrary file-upload vulnerability.
An attacker can exploit this issue to upload arbitrary code and run it in the context of the web server process; other attacks are also possible.
The following products are vulnerable:
ManageEngine OpManager 8.8 through 11.3
ManageEngine Social IT Plus 11.0
ManageEngine IT360 10.4
Multiple ManageEngine Products are prone to an arbitrary file-upload vulnerability.
An attacker can exploit this issue to upload arbitrary code and run it in the context of the web server process; other attacks are also possible.
The following products are vulnerable:
ManageEngine OpManager 8.8 through 11.3
ManageEngine Social IT Plus 11.0
ManageEngine IT360 10.4
Exploit / POC
Multiple ManageEngine Products CVE-2014-6034 Arbitrary File Upload Vulnerability
Attackers can exploit this issue through a browser.
The following exploit is available:
Attackers can exploit this issue through a browser.
The following exploit is available:
Solution / Fix
Multiple ManageEngine Products CVE-2014-6034 Arbitrary File Upload Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Multiple ManageEngine Products CVE-2014-6034 Arbitrary File Upload Vulnerability
References:
References:
- OpManager Homepage (ManageEngine)