CVE Feed

    Dashboard / CVE / CVE-2014-1671

    CVE-2014-1671

    Multiple SQL injection vulnerabilities in Dell KACE K1000 5.4.76847 and possibly earlier allow remote attackers or remote authenticated users to execute arbitrary SQL commands via the macAddress element in a (1) getUploadPath or (2) getKBot SOAP request to service/kbot_service.php; the ID parameter to (3) userui/advisory_detail.php or (4) userui/ticket.php; and the (5) ORDER[] parameter to userui/ticket_list.php.

    Published:Jan 26, 2014
    Last Modified:Apr 11, 2025
    EPS:Jan 26, 2014
    EPSS Score:0.00342
    CVSS Score:6.5

    Affected Products

    Vendor
    Dell
    Product
    Kace K1000 Systems Management Appliance
    Vendor
    Dell
    Product
    Kace K1000 Systems Management Appliance Software
    Vendor
    Dell
    Product
    Kace K1000 Systems Management Virtual Appliance
    Vendor
    Dell
    Product
    Kace K1100s Systems Management Appliance
    Vendor
    Dell
    Product
    Kace K1200s Systems Management Appliance

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High