Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r7hm-265q-g66c

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allow remote attackers or remote authenticated users to read arbitrary files via a full pathname in the schFilePath parameter to the (1) CSVServlet or (2) CReportPDFServlet servlet.

Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allow remote attackers or remote authenticated users to read arbitrary files via a full pathname in the schFilePath parameter to the (1) CSVServlet or (2) CReportPDFServlet servlet.

EPSS

Процентиль: 100%
0.90975
Критический

Дефекты

CWE-22

Связанные уязвимости

nvd
около 11 лет назад

Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allow remote attackers or remote authenticated users to read arbitrary files via a full pathname in the schFilePath parameter to the (1) CSVServlet or (2) CReportPDFServlet servlet.

EPSS

Процентиль: 100%
0.90975
Критический

Дефекты

CWE-22