Multiple ManageEngine Products CVE-2014-7866 Arbitrary File Upload Vulnerabilities
BID:71001
Info
Multiple ManageEngine Products CVE-2014-7866 Arbitrary File Upload Vulnerabilities
| Bugtraq ID: | 71001 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-7866 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 10 2014 12:00AM |
| Updated: | May 12 2015 07:35PM |
| Credit: | Pedro Ribeiro, Agile Information Security |
| Vulnerable: |
ZOHO Corporation ManageEngine Social IT Plus 11.0 ZOHO Corporation ManageEngine OpManager 8.8 ZOHO Corporation ManageEngine OpManager 11.4 ZOHO Corporation ManageEngine OpManager 11.3 ZOHO Corporation ManageEngine OpManager 10.0 ZOHO Corporation ManageEngine IT360 10.4 ZOHO Corporation ManageEngine IT360 10.3 |
| Not Vulnerable: | |
Discussion
Multiple ManageEngine Products CVE-2014-7866 Arbitrary File Upload Vulnerabilities
Multiple ManageEngine Products are prone to multiple arbitrary file-upload vulnerabilities.
An attacker can exploit this issue to upload arbitrary code and run it in the context of the web server process; other attacks are also possible.
Multiple ManageEngine Products are prone to multiple arbitrary file-upload vulnerabilities.
An attacker can exploit this issue to upload arbitrary code and run it in the context of the web server process; other attacks are also possible.
Exploit / POC
Multiple ManageEngine Products CVE-2014-7866 Arbitrary File Upload Vulnerabilities
Attackers can exploit these issues through a browser.
The following example inputs are available:
POST /servlet/MigrateLEEData?fileName=../tomcat/webapps/warfile.war%00
POST /servlet/MigrateCentralData?operation=downloadFileFromProbe&zipFileName=../tomcat/webapps/warfile.war%00
Attackers can exploit these issues through a browser.
The following example inputs are available:
POST /servlet/MigrateLEEData?fileName=../tomcat/webapps/warfile.war%00
POST /servlet/MigrateCentralData?operation=downloadFileFromProbe&zipFileName=../tomcat/webapps/warfile.war%00
Solution / Fix
Multiple ManageEngine Products CVE-2014-7866 Arbitrary File Upload Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Multiple ManageEngine Products CVE-2014-7866 Arbitrary File Upload Vulnerabilities
References:
References:
- OpManager Homepage (ManageEngine)