First published: Fri Jan 17 2020(Updated: )
Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90055 allows remote attackers to write to and execute arbitrary files as SYSTEM via a .. (dot dot) in the filename parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Desktop Central | >=7.0<=9.0 | |
Zohocorp Manageengine Desktop Central Managed Service Providers | >=7.0<=9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5007 is a directory traversal vulnerability in ZOHO ManageEngine Desktop Central and Desktop Central Managed Service Providers.
CVE-2014-5007 allows remote attackers to write and execute arbitrary files on the affected system.
CVE-2014-5007 has a severity rating of 9.8 (Critical).
Update ZOHO ManageEngine Desktop Central to version 9 build 90055 or later to fix CVE-2014-5007.
You can find more information about CVE-2014-5007 in the following references: [http://seclists.org/fulldisclosure/2014/Aug/88](http://seclists.org/fulldisclosure/2014/Aug/88) and [https://www.manageengine.com/products/desktop-central/remote-code-execution.html](https://www.manageengine.com/products/desktop-central/remote-code-execution.html).