Логотип exploitDog
bind:CVE-2018-11137
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-11137

Количество 2

Количество 2

nvd логотип

CVE-2018-11137

больше 7 лет назад

The 'checksum' parameter of the '/common/download_attachment.php' script in the Quest KACE System Management Appliance 8.0.318 can be abused to read arbitrary files with 'www' privileges via Directory Traversal. No administrator privileges are needed to execute this script.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-f57x-72hm-jqw4

больше 3 лет назад

The 'checksum' parameter of the '/common/download_attachment.php' script in the Quest KACE System Management Appliance 8.0.318 can be abused to read arbitrary files with 'www' privileges via Directory Traversal. No administrator privileges are needed to execute this script.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-11137

The 'checksum' parameter of the '/common/download_attachment.php' script in the Quest KACE System Management Appliance 8.0.318 can be abused to read arbitrary files with 'www' privileges via Directory Traversal. No administrator privileges are needed to execute this script.

CVSS3: 6.5
0%
Низкий
больше 7 лет назад
github логотип
GHSA-f57x-72hm-jqw4

The 'checksum' parameter of the '/common/download_attachment.php' script in the Quest KACE System Management Appliance 8.0.318 can be abused to read arbitrary files with 'www' privileges via Directory Traversal. No administrator privileges are needed to execute this script.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу