Critical severity9.8NVD Advisory· Published Jan 17, 2020· Updated Jun 17, 2026
CVE-2014-5007
CVE-2014-5007
Description
Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90055 allows remote attackers to write to and execute arbitrary files as SYSTEM via a .. (dot dot) in the filename parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:a:zohocorp:manageengine_desktop_central:*:*:*:*:*:*:*:*Range: >=7.0,<=9.0
- cpe:2.3:a:zohocorp:manageengine_desktop_central_managed_service_providers:*:*:*:*:*:*:*:*Range: >=7.0,<=9.0
- ZOHO ManageEngine/Desktop Central Managed Service Providers (MSP) editiondescription
- Range: <9 build 90055
- Range: <9 build 90055
Patches
Vulnerability mechanics
References
2- seclists.org/fulldisclosure/2014/Aug/88nvdExploitMailing ListThird Party Advisory
- www.manageengine.com/products/desktop-central/remote-code-execution.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.