CVE-2014-5007: Zohocorp ManageEngine Desktop Central
Critical severity, CVSS 9.8. EPSS: 37.3% chance of exploitation in the next 30 days.
Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90055 allows remote attackers to write to and execute arbitrary files as SYSTEM via a .. (dot dot) in the filename parameter.
Affected products
- Zohocorp ManageEngine Desktop Central: from 7.0, up to and including 9.0
- Zohocorp ManageEngine Desktop Central Managed Service Providers: from 7.0, up to and including 9.0
Published 2020-01-17. Last modified 2026-06-17.