Directory Traversal Vulnerability in ManageEngine Password Manager Pro
CVE-2014-9372

Currently unrated

Key Information:

Vendor
CVE Published:
16 December 2014

Summary

A directory traversal vulnerability exists in the UploadAccountActivities servlet of ManageEngine Password Manager Pro prior to version 7103. This flaw enables remote attackers to manipulate file paths and delete arbitrary files on the server by including a sequence of dot-dot-slash (../) characters in the filenames. By exploiting this vulnerability, attackers may compromise the integrity of the server, leading to unauthorized access and potential data loss.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.