VYPR

Manageengine Firewall Analyzer

Sign in to watch

by Zohocorp

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-14123Hig0.588.80.04Sep 4, 2017Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section. Any user can upload files with any extensions. By uploading a PHP file to the server, an attacker can cause it to execute in the server context, as demonstrated by /itplus/FileStorage/302/shell.jsp.
CVE-2015-7781Hig0.497.50.07Jun 27, 2017ManageEngine Firewall Analyzer before 8.0 does not restrict access permissions.