CVE-2014-5302 – ManageEngine Shell Upload / Directory Traversal
https://notcve.org/view.php?id=CVE-2014-5302
Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4 allows remote authenticated users to execute arbitrary code. Existe una vulnerabilidad de salto de directorio en ServiceDesk Plus y Plus MSP de la v5 a la v9.0 v9030; AssetExplorer de la v4 a la v6.1; SupportCenter de la v5 a la v7.9 y en IT360 de la v8 a la v10.4 que permite que los usuarios remotos autenticados ejecuten código arbitrario. ManageEngine products Service Desk Plus, Asset Explorer, Support Center, and IT360 suffer from file upload and directory traversal vulnerabilities. • http://packetstormsecurity.com/files/129806/ManageEngine-Shell-Upload-Directory-Traversal.html http://seclists.org/fulldisclosure/2015/Jan/12 http://seclists.org/fulldisclosure/2015/Jan/5 http://secunia.com/advisories/62105 http://secunia.com/advisories/62121 http://www.securityfocus.com/archive/1/534377/100/0/threaded https://exchange.xforce.ibmcloud.com/vulnerabilities/99611 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •
CVE-2014-5301 – ManageEngine (Multiple Products) - (Authenticated) Arbitrary File Upload
https://notcve.org/view.php?id=CVE-2014-5301
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4. Existe una vulnerabilidad de salto de directorio en ServiceDesk Plus MSP de la v5 a la v9.0 v9030; AssetExplorer de la v4 a la v6.1; SupportCenter de la v5 a la v7.9 y en IT360 de la v8 a la v10.4. ManageEngine products Service Desk Plus, Asset Explorer, Support Center, and IT360 suffer from file upload and directory traversal vulnerabilities. • https://www.exploit-db.com/exploits/35845 http://packetstormsecurity.com/files/129806/ManageEngine-Shell-Upload-Directory-Traversal.html http://packetstormsecurity.com/files/130020/ManageEngine-Multiple-Products-Authenticated-File-Upload.html http://seclists.org/fulldisclosure/2015/Jan/5 http://secunia.com/advisories/62105 http://www.securityfocus.com/archive/1/534377/100/0/threaded https://exchange.xforce.ibmcloud.com/vulnerabilities/99610 https://seclists.org/fulldisclosure/2015/Jan/5 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •