peter bassill · operator
$ cve CVE-2014-5446 JSON

CVE-2014-5446 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 54.7% (pctl 99)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in the DisplayChartPDF servlet in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allows remote attackers and remote authenticated users to read arbitrary files via a .. (dot dot) in the filename parameter.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS54.72% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2014-12-04
Last modified2026-06-17

Affected (2)

VendorProduct
zohocorpmanageengine it360
zohocorpmanageengine netflow analyzer

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD