The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter.
References
Configurations
History
No history.
Information
Published : 2017-09-28 01:29
Updated : 2025-04-20 01:37
NVD link : CVE-2015-8249
Mitre link : CVE-2015-8249
CVE.ORG link : CVE-2015-8249
JSON object : View
Products Affected
manageengine
- desktop_central
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type