NONE · 0

CVE-2014-125113

An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System Management Appliance version 5.0 - 5.3, 5.4 prior to 5.4.76849, and 5.5 prior to 5.5.90547 in the downloa...

Vulnerability Description

An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System Management Appliance version 5.0 - 5.3, 5.4 prior to 5.4.76849, and 5.5 prior to 5.5.90547 in the download_agent.php endpoint. An attacker can upload arbitrary PHP files to a temporary web-accessible directory, which are later executed through inclusion in backend code that loads files under attacker-controlled paths.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-125113?

CVE-2014-125113 is a documented vulnerability. An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System Management Appliance version 5.0 - 5.3, 5.4 prior to 5.4.76849, and 5.5 prior to 5.5.90547 in the downloa...

How severe is CVE-2014-125113?

CVSS scoring is not yet available for CVE-2014-125113. Check NVD for updates.

Is there a patch for CVE-2014-125113?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.