Security Advisory

CVE-2014-5007

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-01-17 21:59:55
Last updated 2024-08-06 11:34:37
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90055 allows remote attackers to write to and execute arbitrary files as SYSTEM via a .. (dot dot) in the filename parameter.