Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:MISC:MANAGENGINE-EVNTLG-CE

Severity

Major

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

ManageEngine EventLog Analyzer agentUpload Directory Traversal

Release Date

2014/10/06

Update Number

2427

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: ManageEngine EventLog Analyzer agentUpload Directory Traversal


This signature detects directory traversal attempts on ManageEngine EventLog. Successful attack attempts could allow an attacker to view or overwrite sensitive system files.

Extended Description

Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 allows remote attackers to execute arbitrary code by uploading a ZIP file which contains an executable file with .. (dot dot) sequences in its name, then accessing the executable via a direct request to the file under the web root. Fixed in Build 11072.

Affected Products

  • Zohocorp manageengine_eventlog_analyzer 8.2
  • Zohocorp manageengine_eventlog_analyzer 9.0

References

  • BugTraq: 69482
  • CVE: CVE-2014-6037
  • URL: https://www.mogwaisecurity.de/advisories/MSA-2014-01.txt
  • URL: http://seclists.org/fulldisclosure/2014/Aug/86

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out