Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-11133 PoC — Quest KACE System Management Appliance 跨站脚本漏洞

Source
Associated Vulnerability
Title:Quest KACE System Management Appliance 跨站脚本漏洞 (CVE-2018-11133)
Description:Quest KACE System Management Appliance是美国Quest Software公司的一款IT资产管理设备。 Quest KACE System Management Appliance 8.0.318版本中的‘/common/run_cross_report.php’脚本的‘fmt’参数存在跨站脚本漏洞。远程攻击者可利用该漏洞注入任意的Web脚本或HTML。
Description
The 'fmt' parameter of the '/common/run_cross_report.php' script in the the Quest KACE System Management Appliance 8.0.318 is vulnerable to cross-site scripting.
File Snapshot

id: CVE-2018-11133 info: name: Quest KACE SMA /common/run_cross_report.php 'fmt' XSS author: ia ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.