peter bassill · operator
$ cve CVE-2014-6037 JSON

CVE-2014-6037 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 84.2% (pctl 100)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 allows remote attackers to execute arbitrary code by uploading a ZIP file which contains an executable file with .. (dot dot) sequences in its name, then accessing the executable via a direct request to the file under the web root. Fixed in Build 11072.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS84.18% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2014-10-26
Last modified2026-06-17

Affected (1)

VendorProduct
zohocorpmanageengine eventlog analyzer

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD