CVE-2014-5301 is a directory traversal vulnerability in several ManageEngine products (ServiceDesk Plus MSP v5 to v9.0 v9030, AssetExplorer v4 to v6.1, SupportCenter v5 to v7.9, IT360 v8 to v10.4). Authenticated users, including those using default low-privilege guest accounts, can exploit a file upload endpoint to perform directory traversal and upload malicious EAR files. This results in remote code execution as SYSTEM/root on the affected server. The vulnerability is particularly critical due to the prevalence of default accounts and the high privileges obtained upon exploitation. A Metasploit module exists for this vulnerability.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (manageengine_auth_upload.rb) that exploits a directory traversal vulnerability (CVE-2014-5301) in several ManageEngine products (ServiceDesk Plus, AssetExplorer, SupportCenter, IT360). The exploit targets authenticated file upload endpoints, abusing improper handling of '../' sequences to write arbitrary files to the server filesystem. The module attempts to authenticate using default or provided credentials, or a pre-authenticated session cookie. It then uploads a malicious EAR/WAR file containing a Java payload (such as a reverse shell), and triggers it to achieve remote code execution. The module is weaponized, supporting multiple product versions and platforms (Windows and Linux), and is part of the Metasploit framework. The main network endpoints targeted are /workorder/Attachment.jsp and /common/FileAttachment.jsp, which are used for file uploads in the affected products.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.