E20-100s1
CVSS:
9.0 (AV:N/AC:L/Au:N/C:P/I:P/A:C)
False Positive:
t
Variants:
9
Year:
2019
Description
An OS command injection vulnerability exists in Dell KACE K1000 versions before 6.4.120822, due to lack of sanitization of user-supplied data. By sending a crafted kuid parameter in a HTTP request to /service/krashrpt.php, a remote unauthenticated attacker may execute arbitrary OS commands as the user www.
CVE
References
MSB
BID
ExploitDB
Secunia
Security Tracker
Metasploit
ZDI
OSVDB
{}