CVE-2019-13078
- EPSS 1.24%
- Veröffentlicht 06.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:24:09
Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitrary commands against the database. The affected component is /common/user_profile.php. The affected p...
CVE-2019-13077
- EPSS 0.96%
- Veröffentlicht 06.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:24:09
Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via the sam_detail_titled.php SAM_TYPE parameter) that allows an attacker to create a malicious link in order to attack authenticated users.
CVE-2019-13076
- EPSS 1.24%
- Veröffentlicht 06.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:24:09
Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitrary commands against the database. The affected component is /userui/ticket_list.php, and affected pa...
CVE-2019-12918
- EPSS 1.05%
- Veröffentlicht 06.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:23:49
Quest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file is software_library.php and affected parameters are order[0][column] and order[0][dir].
CVE-2019-12917
- EPSS 0.96%
- Veröffentlicht 06.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:23:48
A reflected XSS vulnerability exists in Quest KACE Systems Management Appliance Server Center 9.1.317 affecting the userui/software_library.php component via the PATH_INFO.
- EPSS 2.42%
- Veröffentlicht 08.07.2019 18:15:10
- Zuletzt bearbeitet 21.11.2024 04:20:16
Quest KACE, all versions prior to version 8.0.x, 8.1.x, and 9.0.x, allows unintentional access to the appliance leveraging functions of the troubleshooting tools located in the administrator user interface.
CVE-2019-11604
- EPSS 1.78%
- Veröffentlicht 24.05.2019 17:29:02
- Zuletzt bearbeitet 21.11.2024 04:21:26
An issue was discovered in Quest KACE Systems Management Appliance before 9.1. The script at /service/kbot_service_notsoap.php is vulnerable to unauthenticated reflected XSS when user-supplied input to the METHOD GET parameter is processed by the web...
CVE-2017-12567
- EPSS 1.23%
- Veröffentlicht 07.08.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
SQL injection exists in Quest KACE Asset Management Appliance 6.4.120822 through 7.2, Systems Management Appliance 6.4.120822 through 7.2.101, and K1000 as a Service 7.0 through 7.2.