Vulnerabilities > Landesk > High

DATE CVE VULNERABILITY TITLE RISK
2012-02-18 CVE-2012-1195 Permissions, Privileges, and Access Controls vulnerability in Landesk Lenovo Thinkmanagement Console 9.0.3
Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup web service in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via a PutUpdateFileCore command in a RunAMTCommand SOAP request, then accessing the file via a direct request to the file in the web root.
network
low complexity
landesk CWE-264
7.5
2010-11-15 CVE-2010-2892 Improper Input Validation vulnerability in Landesk Management Gateway
gsb/drivers.php in LANDesk Management Gateway 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the DRIVES parameter, as demonstrated by a cross-site request forgery (CSRF) attack.
network
landesk CWE-20
8.5
2009-02-20 CVE-2008-6195 Path Traversal vulnerability in Landesk Management Suite 8.7/8.8
Directory traversal vulnerability in the PXE TFTP Service (PXEMTFTP.exe) in LANDesk Management Suite (LDMS) 8.80.1.1 and earlier allows remote attackers to read arbitrary files via a subdirectory name followed by ".." sequences, a different vulnerability than CVE-2008-1643.
network
low complexity
landesk CWE-22
7.8