vendor:
DesktopCentral
by:
Unknown
N/A
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: DesktopCentral
Affected Version From: DesktopCentral versions < 80293
Affected Version To: Not mentioned
Patch Exists: YES
Related CWE: Not mentioned
CPE: Not mentioned
Platforms Tested: Not mentioned
2013
DesktopCentral Arbitrary File Upload Vulnerability
ManageEngine DesktopCentral 8.0.0 build 80293 and below suffer from an arbitrary file upload vulnerability that can be leveraged to gain arbitrary code execution on the server. The code run on the server in this fashion will execute as NT-AUTHORITYSYSTEM. The problem exists in the AgentLogUploadServlet. This servlet takes input from HTTP POST and constructs an output file on the server without performing any sanitisation or even checking if the caller is authenticated. Due to the way the path is constructed it is possible to traverse to the application web root and create a script file that will be executed when called from a web browser.
Mitigation:
Apply the patch supplied by the vendor (Patch 80293)