CVE-2014-5006: Path Traversal
Published Oct 21, 2014
·Updated
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter to mdm/mdmLogUploader.
Affected Software
1 affected component
ZohoCorp Manageengine Desktop Central<=9.0
Event History
Oct 21, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5006?
CVE-2014-5006 is rated as a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2014-5006?
The recommended fix for CVE-2014-5006 is to upgrade to ManageEngine Desktop Central version 9 build 90055 or later.
3
What systems are affected by CVE-2014-5006?
CVE-2014-5006 affects versions of ManageEngine Desktop Central prior to 9 build 90055.
4
What type of attack can exploit CVE-2014-5006?
CVE-2014-5006 can be exploited via directory traversal attacks that allow arbitrary file accesses.
5
Is user authentication required to exploit CVE-2014-5006?
No user authentication is required to exploit CVE-2014-5006, making it particularly dangerous.