CVE-2018-5404

MEDIUM

Quest Kace K1000 <9.0.270 - Blind SQL Injection

Title source: llm

Description

The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows an authenticated, remote attacker with least privileges ('User Console Only' role) to potentially exploit multiple Blind SQL Injection vulnerabilities to retrieve sensitive information from the database or copy the entire database. An authenticated remote attacker could leverage Blind SQL injections to obtain sensitive data.

Exploits (1)

exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/46956

Scores

CVSS v3 6.5
EPSS 0.0046
EPSS Percentile 64.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-89
Status published
Products (1)
quest/kace_systems_management_appliance_firmware < 9.0.270
Published Jun 03, 2019
Tracked Since Feb 18, 2026