Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-20504 PoC — Quest Software KACE K1000 Systems Management Appliance 注入漏洞

Source
Associated Vulnerability
Title:Quest Software KACE K1000 Systems Management Appliance 注入漏洞 (CVE-2019-20504)
Description:Quest Software KACE K1000 Systems Management Appliance(KACE SMA)是美国Quest Software公司的一款系统管理设备。 Quest Software KACE SMA 6.4 SP3 (6.4.120822)之前版本中的service/krashrpt.php文件存在安全漏洞。远程攻击者可借助带有shell元字符的‘kuid’参数利用该漏洞执行代码。
Description
service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via shell metacharacters in the kuid parameter.
File Snapshot

id: CVE-2019-20504 info: name: Dell KACE Systems Management Appliance (K1000) 6.4.120756 - Remote ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.