CVE-2014-5362: Input Validation
The admin interface in Landesk Management Suite 9.6 and earlier allows remote attackers to conduct remote file inclusion attacks involving ASPX pages from third-party sites via the d parameter to (1) ldms/smactionfrm.asp or (2) remote/frmcoremainfrm.aspx; or the (3) top parameter to remote/frmsplitfrm.aspx.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5362?
CVE-2014-5362 is rated as a high severity vulnerability due to its potential for remote file inclusion attacks.
How do I fix CVE-2014-5362?
To fix CVE-2014-5362, update the Landesk Management Suite to version 9.6 or later, as previous versions are vulnerable.
What types of attacks are possible with CVE-2014-5362?
CVE-2014-5362 allows remote attackers to conduct remote file inclusion and potentially execute arbitrary code.
Which software is affected by CVE-2014-5362?
CVE-2014-5362 affects Landesk Management Suite version 9.6 and earlier.
What parameters are involved in the exploitation of CVE-2014-5362?
Exploitations of CVE-2014-5362 involve manipulating the 'd' parameter in specific ASPX pages.