CVE-2014-5301 EXPLOIT
8.8
HIGH · CVSS 3.0 · EPSS 78.4% (pctl 100)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4.
Scoring
| CVSS | 8.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 78.38% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-08-28 |
| Last modified | 2026-06-17 |
Affected (4)
| Vendor | Product |
|---|---|
| manageengine | assetexplorer |
| manageengine | it360 |
| manageengine | servicedesk plus |
| manageengine | supportcenter |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | ManageEngine (Multiple Products) - (Authenticated) Arbitrary File Upload (Metasploit) | 2015-01-20 |
References
- http://packetstormsecurity.com/files/129806/ManageEngine-Shell-Upload-Directory-Traversal.html
- http://packetstormsecurity.com/files/130020/ManageEngine-Multiple-Products-Authenticated-File-Upload.html
- http://seclists.org/fulldisclosure/2015/Jan/5
- http://secunia.com/advisories/62105
- http://www.securityfocus.com/archive/1/534377/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99610
- https://www.exploit-db.com/exploits/35845/
- http://packetstormsecurity.com/files/129806/ManageEngine-Shell-Upload-Directory-Traversal.html
- http://packetstormsecurity.com/files/130020/ManageEngine-Multiple-Products-Authenticated-File-Upload.html
- http://seclists.org/fulldisclosure/2015/Jan/5
- http://secunia.com/advisories/62105
- http://www.securityfocus.com/archive/1/534377/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99610
- https://www.exploit-db.com/exploits/35845/
→ the Explorer · watch your stack · NVD