漏洞描述
Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 allows remote attackers to execute arbitrary code by uploading a ZIP file which contains an executable file with .. (dot dot) sequences in its name, then accessing the executable via a direct request to the file under the web root. Fixed in Build 11072.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.securityfocus.comhttp://www.securityfocus.com/bid/69482↗seclists.orghttp://seclists.org/fulldisclosure/2014/Sep/19↗github.comhttps://github.com/rapid7/metasploit-framework/pull/3732↗osvdb.orghttp://osvdb.org/show/osvdb/110642↗packetstormsecurity.comhttp://packetstormsecurity.com/files/128102/ManageEngine-EventLog-Analyzer-9.9-Authorization-Code-Execution.html↗seclists.orghttp://seclists.org/fulldisclosure/2014/Sep/20↗www.mogwaisecurity.dehttps://www.mogwaisecurity.de/advisories/MSA-2014-01.txt↗seclists.orghttp://seclists.org/fulldisclosure/2014/Sep/1↗seclists.orghttp://seclists.org/fulldisclosure/2014/Aug/86↗