peter bassill · operator
$ cve CVE-2018-5404 JSON

CVE-2018-5404 EXPLOIT

6.5
MEDIUM · CVSS 3.0 · EPSS 3.8% (pctl 90)

Patch early

A public exploit exists.

Description

The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows an authenticated, remote attacker with least privileges ('User Console Only' role) to potentially exploit multiple Blind SQL Injection vulnerabilities to retrieve sensitive information from the database or copy the entire database. An authenticated remote attacker could leverage Blind SQL injections to obtain sensitive data.

Scoring

CVSS6.5 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS3.77% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2019-06-03
Last modified2026-06-17

Affected (2)

VendorProduct
questkace systems management appliance
questkace systems management appliance firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD