First published: Tue Sep 19 2017(Updated: )
The admin interface in Landesk Management Suite 9.6 and earlier allows remote attackers to conduct remote file inclusion attacks involving ASPX pages from third-party sites via the d parameter to (1) ldms/sm_actionfrm.asp or (2) remote/frm_coremainfrm.aspx; or the (3) top parameter to remote/frm_splitfrm.aspx.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti LANDESK Management Suite | <=9.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5362 is rated as a high severity vulnerability due to its potential for remote file inclusion attacks.
To fix CVE-2014-5362, update the Landesk Management Suite to version 9.6 or later, as previous versions are vulnerable.
CVE-2014-5362 allows remote attackers to conduct remote file inclusion and potentially execute arbitrary code.
CVE-2014-5362 affects Landesk Management Suite version 9.6 and earlier.
Exploitations of CVE-2014-5362 involve manipulating the 'd' parameter in specific ASPX pages.