Loading
Directory traversal vulnerability in the multipartRequest servlet in ZOHO ManageEngine OpManager 11.3 and earlier, Social IT Plus 11.0, and IT360 10.3, 10.4, and earlier allows remote attackers or remote authenticated users to delete arbitrary files via a .. (dot dot) in the fileName parameter.
Use CWE-22, Zohocorp vendor hub and Manageengine Opmanager product page to widen CVE-2014-6036 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-29535, CVE-2021-44514 and CVE-2023-47211 for nearby disclosures in the same product family.