← All CVEs

CVE-2014-100002

medium · 5

Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the attach parameter to WorkOrder.do in the file attachment for a new ticket.

5
CVSS
59.9%
EPSS (exploit prob.)
99th
EPSS percentile
2015-01-13
Published

AV:N/AC:L/Au:N/C:P/I:N/A:N

Weaknesses

CWE-22

Affected products

VendorProductAffected versions
zohocorpmanageengine_supportcenter_plus<= 7.9

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-100002