peter bassill · operator
$ cve CVE-2014-1671 JSON

CVE-2014-1671 EXPLOIT

6.5
MEDIUM · CVSS 2.0 · EPSS 1.9% (pctl 80)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in Dell KACE K1000 5.4.76847 and possibly earlier allow remote attackers or remote authenticated users to execute arbitrary SQL commands via the macAddress element in a (1) getUploadPath or (2) getKBot SOAP request to service/kbot_service.php; the ID parameter to (3) userui/advisory_detail.php or (4) userui/ticket.php; and the (5) ORDER[] parameter to userui/ticket_list.php.

Scoring

CVSS6.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS1.95% — more likely to be exploited than 80% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2014-01-26
Last modified2026-06-17

Affected (5)

VendorProduct
dellkace k1000 systems management appliance
dellkace k1000 systems management appliance software
dellkace k1000 systems management virtual appliance
dellkace k1100s systems management appliance
dellkace k1200s systems management appliance

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD