Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticated user and can be abused to execute arbitrary commands on the system. This script is vulnerable to command injection via the unsanitized user input 'TEST_SERVER' sent to the script via the POST method.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Quest KACE System Management Appliance 操作系统命令注入漏洞
Vulnerability Description
Quest KACE System Management Appliance是美国Quest Software公司的一款IT资产管理设备。 Quest KACE System Management Appliance 8.0.318版本中存在操作系统命令注入漏洞,该漏洞源于任意的认证用户都可以访问‘/common/ajax_email_connection_test.php’脚本。攻击者可借助POST方法通过‘TEST_SERVER’发送未过滤的用户输入利用该漏洞在系统上执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A