CVE-2014-5302

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
28/08/2017
Last modified:
20/04/2025

Description

Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4 allows remote authenticated users to execute arbitrary code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:manageengine:servicedesk_plus:-:*:*:*:*:*:*:*
cpe:2.3:a:manageengine:assetexplorer:-:*:*:*:*:*:*:*
cpe:2.3:a:manageengine:supportcenter:-:*:*:*:*:*:*:*
cpe:2.3:a:manageengine:it360:-:*:*:*:*:*:*:*