Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section. Any user can upload files with any extensions. By uploading a PHP file to the server, an attacker can cause it to execute in the server context, as demonstrated by /itplus/FileStorage/302/shell.jsp.
References
Link | Resource |
---|---|
https://pitstop.manageengine.com/portal/kb/articles/latest-consolidated-patch | Patch Vendor Advisory |
https://blogs.securiteam.com/index.php/archives/3228 | Exploit Patch Third Party Advisory |
Configurations
Information
Published : 2017-09-04 13:29
Updated : 2020-10-01 10:51
NVD link : CVE-2017-14123
Mitre link : CVE-2017-14123
JSON object : View
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
Products Affected
zohocorp
- manageengine_firewall_analyzer