Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple directory traversal vulnerabilities in ZOHO ManageEngine OpManager 8 (build 88xx) through 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allow remote attackers or remote authenticated users to write and execute arbitrary files via a .. (dot dot) in the (1) fileName parameter to the MigrateLEEData servlet or (2) zipFileName parameter in a downloadFileFromProbe operation to the MigrateCentralData servlet.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
多款ZOHO产品目录遍历漏洞
Vulnerability Description
ZOHO ManageEngine OpManager、IT360和Social IT Plus都是美国卓豪(ZOHO)公司的产品。ManageEngine OpManager是一套网络、服务器及虚拟化监控软件;ManageEngine IT360是一套IT运维综合治理平台;ManageEngine Social IT Plus是一套面向IT团队推出的社交网络协作平台。 多款ZOHO产品的MigrateCentralData servlet和MigrateLEEData servlet中存在目录遍历漏洞。
CVSS Information
N/A
Vulnerability Type
N/A