Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-11141

Опубликовано: 31 мая 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

The 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE System Management Virtual Appliance 8.0.318 can be abused to write and delete files respectively via Directory Traversal. Files can be at any location where the 'www' user has write permissions.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:quest:kace_system_management_appliance:8.0.318:*:*:*:*:*:*:*

EPSS

Процентиль: 72%
0.00742
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

The 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE System Management Virtual Appliance 8.0.318 can be abused to write and delete files respectively via Directory Traversal. Files can be at any location where the 'www' user has write permissions.

EPSS

Процентиль: 72%
0.00742
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-22