Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allow remote attackers or remote authenticated users to read arbitrary files via a full pathname in the schFilePath parameter to the (1) CSVServlet or (2) CReportPDFServlet servlet.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ZOHO ManageEngine Netflow Analyzer和IT360 绝对路径遍历漏洞
Vulnerability Description
ZOHO ManageEngine Netflow Analyzer和IT360都是美国卓豪(ZOHO)公司的产品。ManageEngine Netflow Analyzer是一套基于Web的带宽监控工具;ManageEngine IT360是一套IT运维综合治理平台。 ZOHO ManageEngine Netflow Analyzer 8.6版本至10.2版本和IT360 10.3版本中存在绝对路径遍历漏洞,该漏洞源于CSVServlet和CReportPDFServlet servlet没有充分过滤
CVSS Information
N/A
Vulnerability Type
N/A