Back to Database
Status published
High
CVE-2014-5301
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0...
Vulnerability Description
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-5301
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.exploit-db.com/exploits/35845/
- http://secunia.com/advisories/62105
- http://seclists.org/fulldisclosure/2015/Jan/5
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99610
- http://packetstormsecurity.com/files/130020/ManageEngine-Multiple-Products-Authenticated-File-Upload.html
- http://packetstormsecurity.com/files/129806/ManageEngine-Shell-Upload-Directory-Traversal.html
- http://www.securityfocus.com/archive/1/534377/100/0/threaded
More from manageengine
View All →CVE-2021-28960
Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command...
Critical
9.8
CVE-2020-19554
Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174...
Medium
6.1
CVE-2018-15608
Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the...
Medium
6.1
CVE-2015-8249
The FileUploadServlet class in ManageEngine Desktop Central 9 before build...
Critical
9.8
CVE-2015-1480
ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows...
Medium
4
Affected Vendor
manageengine
View all reports →Affected Software
servicedesk plus, assetexplorer, supportcenter, it360
Vulnerable Versions:
Unknown
Timeline
Official Publish:
August 28th, 2017
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.