cve/2015/CVE-2015-5149.md
2024-06-18 02:51:15 +02:00

884 B

CVE-2015-5149

Description

Directory traversal vulnerability in Zoho ManageEngine SupportCenter Plus 7.90 allows remote authenticated users to write to arbitrary files via a .. (dot dot) in the component parameter in the Request component to workorder/Attachment.jsp.

POC

Reference

Github

No PoCs found on GitHub currently.