Filtered by vendor Quest Subscriptions
Total 131 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-35203 1 Quest 1 Policy Authority For Unified Communications 2024-08-04 6.1 Medium
Reflected XSS in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via a specially crafted link to the initFile.jsp file via the msg parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
CVE-2020-8868 1 Quest 1 Foglight Evolve 2024-08-04 9.8 Critical
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest Foglight Evolve 9.0.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the __service__ user account. The product contains a hard-coded password for this account. An attacker can leverage this vulnerability to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-9553.
CVE-2021-44030 1 Quest 1 Kace Desktop Authority 2024-08-04 6.1 Medium
Quest KACE Desktop Authority before 11.2 allows XSS because it does not prevent untrusted HTML from reaching the jQuery.htmlPrefilter method of jQuery.
CVE-2021-44028 1 Quest 1 Kace Desktop Authority 2024-08-04 5.5 Medium
XXE can occur in Quest KACE Desktop Authority before 11.2 because the log4net configuration file might be controlled by an attacker, a related issue to CVE-2018-1285.
CVE-2021-44031 1 Quest 1 Kace Desktop Authority 2024-08-04 9.8 Critical
An issue was discovered in Quest KACE Desktop Authority before 11.2. /dacomponentui/profiles/profileitems/outlooksettings/Insertimage.aspx contains a vulnerability that could allow pre-authentication remote code execution. An attacker could upload a .ASP file to reside at /images/{GUID}/{filename}.
CVE-2021-44029 1 Quest 1 Kace Desktop Authority 2024-08-04 9.8 Critical
An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remote code through a deserialization exploitation in the RadAsyncUpload function of ASP.NET AJAX. An attacker can leverage this vulnerability when the encryption keys are known (due to the presence of CVE-2017-11317, CVE-2017-11357, or other means). A default setting for the type whitelisting feature in more current versions of ASP.NET AJAX prevents exploitation.
CVE-2022-38220 1 Quest 1 Kace Systems Management Appliance 2024-08-03 6.1 Medium
An XSS vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.1 that may allow remote injection of arbitrary web script or HTML.
CVE-2022-30285 1 Quest 1 Kace Systems Management Appliance 2024-08-03 9.8 Critical
In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible during authentication. This may allow authentication with invalid credentials.
CVE-2022-29807 1 Quest 1 Kace Systems Management Appliance 2024-08-03 9.8 Critical
A SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.0 that can allow for remote code execution via download_agent_installer.php.
CVE-2022-29808 1 Quest 1 Kace Systems Management Appliance 2024-08-03 7.5 High
In Quest KACE Systems Management Appliance (SMA) through 12.0, predictable token generation occurs when appliance linking is enabled.
CVE-2023-33254 1 Quest 1 Kace Systems Deployment Appliance 2024-08-02 6.5 Medium
There is an LDAP bind credentials exposure on KACE Systems Deployment and Remote Site appliances 9.0.146. The captured credentials may provide a higher privilege level on the Active Directory domain. To exploit this, an authenticated attacker edits the user-authentication settings to specify an attacker-controlled LDAP server, clicks the Test Settings button, and captures the cleartext credentials.