Check Point Reference: | CPAI-2014-1851 |
Date Published: | 14 Oct 2014 |
Severity: | Critical |
Last Updated: | Tuesday 14 October, 2014 |
Source: | |
Industry Reference: | CVE-2014-5006 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | ManageEngine DesktopCentral v7 to v9 build 90054 |
Vulnerability Description | A directory traversal vulnerability has been reported in ManageEngine Desktop Central. The vulnerability is due to lack of authentication and insufficient input validation in the mdmLogUploader when processing HTTP requests. A remote unauthenticated attacker can upload arbitrary files to arbitrary locations. |
SmartView Tracker will log the following entries:
Attack Name: Web Server Enforcement Violation.
Attack Information: ManageEngine Desktop Central mdmLogUploader Directory Traversal