CVEs (11)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Quest 1Kace System Management Appliance Nov 21, 2024 May 31, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The 'systemui/settings_network.php' and 'systemui/settings_patching.php' scripts in the Quest KACE System Management Appliance 8.0.318 are accessible only from localhost. This restriction can be bypassed by modifying the...Show more |
1Quest 1Kace System Management Appliance Nov 21, 2024 May 31, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE System Management Virtual Appliance 8.0.318 can be abused to write and delete files respectively via Dire...Show more |
1Quest 1Kace System Management Appliance Nov 21, 2024 May 31, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The 'reportID' parameter received by the '/common/run_report.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injection (in particular, an error-based type). |
1Quest 1Kace System Management Appliance Nov 21, 2024 May 31, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticated user and can be abused to execute arbitrary commands on the system. This script...Show more |
1Quest 1Kace System Management Appliance Nov 5, 2025 May 31, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system. |
1Quest 1Kace System Management Appliance Nov 21, 2024 May 31, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The 'checksum' parameter of the '/common/download_attachment.php' script in the Quest KACE System Management Appliance 8.0.318 can be abused to read arbitrary files with 'www' privileges via Directory Traversal. No admin...Show more |
1Quest 1Kace System Management Appliance Nov 21, 2024 May 31, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The 'orgID' parameter received by the '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injection (in particular, a blind time-based type...Show more |
1Quest 1Kace System Management Appliance Nov 21, 2024 May 31, 2018 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 The script '/adminui/error_details.php' in the Quest KACE System Management Appliance 8.0.318 allows authenticated users to conduct PHP object injection attacks. |
1Quest 1Kace System Management Appliance Nov 21, 2024 May 31, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue managed that runs with root privileges and only allows a set of commands. One of t...Show more |
1Quest 1Kace System Management Appliance Nov 21, 2024 May 31, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The 'fmt' parameter of the '/common/run_cross_report.php' script in the the Quest KACE System Management Appliance 8.0.318 is vulnerable to cross-site scripting. |
1Quest 1Kace System Management Appliance Nov 21, 2024 May 31, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue that runs daemonized with root privileges and only allows a set of commands to be e...Show more |