Логотип exploitDog
bind:CVE-2018-11141
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-11141

Количество 2

Количество 2

nvd логотип

CVE-2018-11141

больше 7 лет назад

The 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE System Management Virtual Appliance 8.0.318 can be abused to write and delete files respectively via Directory Traversal. Files can be at any location where the 'www' user has write permissions.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-j7wq-939h-7prv

больше 3 лет назад

The 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE System Management Virtual Appliance 8.0.318 can be abused to write and delete files respectively via Directory Traversal. Files can be at any location where the 'www' user has write permissions.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-11141

The 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE System Management Virtual Appliance 8.0.318 can be abused to write and delete files respectively via Directory Traversal. Files can be at any location where the 'www' user has write permissions.

CVSS3: 9.8
1%
Низкий
больше 7 лет назад
github логотип
GHSA-j7wq-939h-7prv

The 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE System Management Virtual Appliance 8.0.318 can be abused to write and delete files respectively via Directory Traversal. Files can be at any location where the 'www' user has write permissions.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу