CVE-2013-7390

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
27/01/2020
Last modified:
05/02/2020

Description

Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the webroot.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zohocorp:manageengine_desktop_central:*:*:*:*:*:*:*:* 7.0.0 (including) 8.0.0 (including)