First published: Mon Jan 27 2020(Updated: )
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the webroot.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Desktop Central | >=7.0.0<=8.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2013-7390.
The severity of CVE-2013-7390 is critical with a CVSS score of 9.8.
The affected software of CVE-2013-7390 is Zohocorp Manageengine Desktop Central 7.x and 8.0.0 before build 80293.
The vulnerability CVE-2013-7390 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the webroot.
Yes, upgrading to build 80293 or later of Zohocorp Manageengine Desktop Central 7.x and 8.0.0 fixes the vulnerability.