CVE-2014-5005
21.10.2014, 15:55
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter in an LFU action to statusUpdate.
Vendor | Product | Version |
---|---|---|
zohocorp | manageengine_desktop_central | 𝑥 ≤ 9.0 |
𝑥
= Vulnerable software versions
References