Skip to main content

Vendor/product archive

quest / kace_system_management_appliance CVEs

Beta · best-effort

11 CVEs tagged to quest / kace_system_management_appliance4 Critical, 4 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2018-11142

Published May 31, 2018

The 'systemui/settings_network.php' and 'systemui/settings_patching.php' scripts in the Quest KACE System Management Appliance 8.0.318 are accessible only from localhost. This res…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11141

Published May 31, 2018

The 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE System Management Virtual Appliance 8.0.318 can be abused to wri…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-11140

Published May 31, 2018

The 'reportID' parameter received by the '/common/run_report.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injection (in parti…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-11139

Published May 31, 2018

The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticated user and can be abused to execute arbi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11138

Published May 31, 2018

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary com…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
50.4
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2018-11137

Published May 31, 2018

The 'checksum' parameter of the '/common/download_attachment.php' script in the Quest KACE System Management Appliance 8.0.318 can be abused to read arbitrary files with 'www' pri…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11136

Published May 31, 2018

The 'orgID' parameter received by the '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injectio…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-11134

Published May 31, 2018

In order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue managed that runs with root privileges an…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11132

Published May 31, 2018

In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue that runs daemonized with root privileges…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1