CVE-2014-5362
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
19/09/2017
Last modified:
20/04/2025
Description
The admin interface in Landesk Management Suite 9.6 and earlier allows remote attackers to conduct remote file inclusion attacks involving ASPX pages from third-party sites via the d parameter to (1) ldms/sm_actionfrm.asp or (2) remote/frm_coremainfrm.aspx; or the (3) top parameter to remote/frm_splitfrm.aspx.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:landesk:landesk_management_suite:*:*:*:*:*:*:*:* | 9.6 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://packetstormsecurity.com/files/131496/Landesk-Management-Suite-9.5-RFI-CSRF.html
- http://www.securityfocus.com/archive/1/535286/100/1100/threaded
- http://www.securityfocus.com/bid/74190
- http://www.securitytracker.com/id/1032203
- http://packetstormsecurity.com/files/131496/Landesk-Management-Suite-9.5-RFI-CSRF.html
- http://www.securityfocus.com/archive/1/535286/100/1100/threaded
- http://www.securityfocus.com/bid/74190
- http://www.securitytracker.com/id/1032203



