First published: Thu May 31 2018(Updated: )
The 'checksum' parameter of the '/common/download_attachment.php' script in the Quest KACE System Management Appliance 8.0.318 can be abused to read arbitrary files with 'www' privileges via Directory Traversal. No administrator privileges are needed to execute this script.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Quest KACE System Management Appliance | =8.0.318 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.