CVE-2014-6037

N/A Unknown
Published: October 26, 2014 Modified: May 06, 2026
View on NVD

Description

Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 allows remote attackers to execute arbitrary code by uploading a ZIP file which contains an executable file with .. (dot dot) sequences in its name, then accessing the executable via a direct request to the file under the web root. Fixed in Build 11072.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://www.exploit-db.com/exploits/34519
Source: cve@mitre.org
Exploit
http://www.securityfocus.com/bid/69482
Source: cve@mitre.org
Exploit
http://osvdb.org/show/osvdb/110642
Source: af854a3a-2127-422b-91ae-364da2661108
http://seclists.org/fulldisclosure/2014/Aug/86
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://seclists.org/fulldisclosure/2014/Sep/1
Source: af854a3a-2127-422b-91ae-364da2661108
http://seclists.org/fulldisclosure/2014/Sep/19
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://seclists.org/fulldisclosure/2014/Sep/20
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://www.exploit-db.com/exploits/34519
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://www.securityfocus.com/bid/69482
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
https://github.com/rapid7/metasploit-framework/pull/3732
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
https://www.mogwaisecurity.de/advisories/MSA-2014-01.txt
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

20 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
81.7%
99th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

zohocorp