Show filters
178 Total Results
Displaying 41-50 of 178
Sort by:
Attacker Value
Unknown
CVE-2020-35725
Disclosure Date: January 11, 2021 (last updated February 22, 2025)
Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the /WebCM/index.jsp file via the msg parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
0
Attacker Value
Unknown
CVE-2020-35723
Disclosure Date: January 11, 2021 (last updated February 22, 2025)
Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the ReportPreview.do file via the referer parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
0
Attacker Value
Unknown
CVE-2018-18689
Disclosure Date: January 07, 2021 (last updated February 22, 2025)
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteRange and xref manipulations that are not detected by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects eXpert PDF 12 Ultimate, Expert PDF Reader, Nitro Pro, Nitro Reader, PDF Architect 6, PDF Editor 6 Pro, PDF Experte 9 Ultimate, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, PDF-XChange Editor and Viewer, Perfect PDF 10 Premium, Perfect PDF Reader, Soda PDF, and Soda PDF Desktop.
0
Attacker Value
Unknown
CVE-2020-13482
Disclosure Date: May 25, 2020 (last updated February 21, 2025)
EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.
0
Attacker Value
Unknown
CVE-2020-7646
Disclosure Date: May 07, 2020 (last updated February 21, 2025)
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.
0
Attacker Value
Unknown
CVE-2020-8868
Disclosure Date: March 23, 2020 (last updated February 21, 2025)
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest Foglight Evolve 9.0.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the __service__ user account. The product contains a hard-coded password for this account. An attacker can leverage this vulnerability to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-9553.
0
Attacker Value
Unknown
CVE-2019-20504
Disclosure Date: March 09, 2020 (last updated February 21, 2025)
service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via shell metacharacters in the kuid parameter.
0
Attacker Value
Unknown
CVE-2014-8650
Disclosure Date: December 15, 2019 (last updated November 27, 2024)
python-requests-Kerberos through 0.5 does not handle mutual authentication
0
Attacker Value
Unknown
CVE-2019-13076
Disclosure Date: November 06, 2019 (last updated November 27, 2024)
Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitrary commands against the database. The affected component is /userui/ticket_list.php, and affected parameters are order[0][column] and order[0][dir].
0
Attacker Value
Unknown
CVE-2019-12918
Disclosure Date: November 06, 2019 (last updated November 27, 2024)
Quest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file is software_library.php and affected parameters are order[0][column] and order[0][dir].
0