CVE-2014-5007: Path Traversal
Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90055 allows remote attackers to write to and execute arbitrary files as SYSTEM via a .. (dot dot) in the filename parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2014-5007?
CVE-2014-5007 is a directory traversal vulnerability in ZOHO ManageEngine Desktop Central and Desktop Central Managed Service Providers.
How does CVE-2014-5007 affect ZOHO ManageEngine Desktop Central?
CVE-2014-5007 allows remote attackers to write and execute arbitrary files on the affected system.
What is the severity of CVE-2014-5007?
CVE-2014-5007 has a severity rating of 9.8 (Critical).
How do I fix CVE-2014-5007 in ZOHO ManageEngine Desktop Central?
Update ZOHO ManageEngine Desktop Central to version 9 build 90055 or later to fix CVE-2014-5007.
Where can I find more information about CVE-2014-5007?
You can find more information about CVE-2014-5007 in the following references: [http://seclists.org/fulldisclosure/2014/Aug/88](http://seclists.org/fulldisclosure/2014/Aug/88) and [https://www.manageengine.com/products/desktop-central/remote-code-execution.html](https://www.manageengine.com/products/desktop-central/remote-code-execution.html).