CVE-2014-5362

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
19/09/2017
Last modified:
20/04/2025

Description

The admin interface in Landesk Management Suite 9.6 and earlier allows remote attackers to conduct remote file inclusion attacks involving ASPX pages from third-party sites via the d parameter to (1) ldms/sm_actionfrm.asp or (2) remote/frm_coremainfrm.aspx; or the (3) top parameter to remote/frm_splitfrm.aspx.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:landesk:landesk_management_suite:*:*:*:*:*:*:*:* 9.6 (including)