CVE-2019-13076: SQL Injection
Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitrary commands against the database. The affected component is /userui/ticketlist.php, and affected parameters are order[0][column] and order[0][dir].
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-13076?
CVE-2019-13076 is a vulnerability in Quest KACE Systems Management Appliance Server Center 9.1.317 that allows authenticated users to execute arbitrary commands against the database through SQL injection.
Which component is affected by CVE-2019-13076?
The affected component is /userui/ticket_list.php.
What are the affected parameters in CVE-2019-13076?
The affected parameters are order[0][column] and order[0][dir].
What is the severity of CVE-2019-13076?
CVE-2019-13076 has a severity value of 8.8 (high).
How can I fix CVE-2019-13076?
To fix CVE-2019-13076, it is recommended to update Quest KACE Systems Management Appliance Server Center to a version that is not affected by the vulnerability.