CVE-2018-5406

HIGH

Quest KACE Systems Management Appliance < 9.0.270 - Unauthenticated Privilege Escalation via CORS Misconfiguration

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-5406. PoCs published by SlidingWindow.

AI-analyzed exploit summary The exploit demonstrates Blind SQL Injection vulnerabilities in Dell KACE K1000 Appliance via unsanitized parameters in 'ajax_lookup_list.php' and 'oval_detail.php'. It includes proof-of-concept requests to confirm the vulnerabilities.

Description

The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows a remote attacker to exploit the misconfigured Cross-Origin Resource Sharing (CORS) mechanism. An unauthenticated, remote attacker could exploit this vulnerability to perform sensitive actions such as adding a new administrator account or changing the appliance’s settings. A malicious internal user could also gain administrator privileges of this appliance and use it to visit a malicious link that exploits this vulnerability. This could cause the application to perform sensitive actions such as adding a new administrator account or changing the appliance’s settings. An unauthenticated, remote attacker could add an administrator-level account or change the appliance's settings.

Exploits (1)

exploitdb WORKING POC VERIFIED
by SlidingWindow · textwebappsphp
https://www.exploit-db.com/exploits/46956

The exploit demonstrates Blind SQL Injection vulnerabilities in Dell KACE K1000 Appliance via unsanitized parameters in 'ajax_lookup_list.php' and 'oval_detail.php'. It includes proof-of-concept requests to confirm the vulnerabilities.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Dell KACE K1000 Appliance (versions prior to 9.0.270 PATCH SEC2018_20180410)
Auth required
Prerequisites: Authenticated user with 'User Console Only' or 'Read Only Administrator' rights
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
https://www.kb.cert.org/vuls/id/877837/

Scores

CVSS v3 8.8
EPSS 0.1221
EPSS Percentile 95.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-284
Status published
Products (1)
quest/kace_systems_management_appliance_firmware < 9.0.270
Published Jun 03, 2019
Tracked Since Feb 18, 2026