peter bassill · operator
$ cve CVE-2014-6034 JSON

CVE-2014-6034 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 79% (pctl 100)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet in ZOHO ManageEngine OpManager 8.8 through 11.3, Social IT Plus 11.0, and IT360 10.4 and earlier allows remote attackers or remote authenticated users to write to and execute arbitrary WAR files via a .. (dot dot) in the regionID parameter.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS78.95% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2014-12-04
Last modified2026-06-17

Affected (3)

VendorProduct
zohocorpmanageengine it360
zohocorpmanageengine opmanager
zohocorpmanageengine social it plus

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD