CVE-2014-5005: Path Traversal
Published Oct 21, 2014
·Updated
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter in an LFU action to statusUpdate.
Affected Software
1 affected component
ZohoCorp Manageengine Desktop Central<=9.0
Event History
Oct 21, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5005?
CVE-2014-5005 is considered a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2014-5005?
To fix CVE-2014-5005, upgrade to the latest version of ZOHO ManageEngine Desktop Central, specifically version 9 or later.
3
What type of vulnerability is CVE-2014-5005?
CVE-2014-5005 is a directory traversal vulnerability.
4
What can attackers do exploiting CVE-2014-5005?
Exploiting CVE-2014-5005 allows remote attackers to execute arbitrary code on the affected system.
5
Which software versions are affected by CVE-2014-5005?
CVE-2014-5005 affects ZOHO ManageEngine Desktop Central versions prior to 9 build 90055.