CVE-2018-11141
Summary
| CVE | CVE-2018-11141 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-31 18:29:00 UTC |
| Updated | 2018-06-29 18:52:00 UTC |
| Description | The 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE System Management Virtual Appliance 8.0.318 can be abused to write and delete files respectively via Directory Traversal. Files can be at any location where the 'www' user has write permissions. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Quest | Kace System Management Appliance | 8.0.318 | All | All | All |
| Application | Quest | Kace System Management Appliance | 8.0.318 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Quest KACE System Management Appliance Multiple Vulnerabilities | SecureAuth | MISC | www.coresecurity.com | Exploit, Technical Description, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.