Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in the CollectorConfInfoServlet servlet in ManageEngine NetFlow Analyzer allows remote attackers to execute arbitrary code via a .. (dot dot) in the filename.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ZOHO ManageEngine NetFlow Analyzer 目录遍历漏洞
Vulnerability Description
ZOHO ManageEngine Netflow Analyzer是美国卓豪(ZOHO)公司的一套基于Web的带宽监控工具。该工具通过路由设备分析网路流量并报告跨网路的带宽使用率等。 ZOHO ManageEngine NetFlow Analyzer的CollectorConfInfoServlet servlet中存在目录遍历漏洞。远程攻击者可借助文件名中的目录遍历字符‘..’利用该漏洞执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A