CVE-2014-5005
21.10.2014, 15:55
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter in an LFU action to statusUpdate.
| Vendor | Product | Version |
|---|---|---|
| zohocorp | manageengine_desktop_central | 𝑥 ≤ 9.0 |
𝑥
= Vulnerable software versions
References