HomeDellCVE-2014-1671

CVE-2014-1671

UNKNOWN
6.5CVSS
Published: 2014-01-26
Updated: 2025-04-11
AI Analysis

Description

Multiple SQL injection vulnerabilities in Dell KACE K1000 5.4.76847 and possibly earlier allow remote attackers or remote authenticated users to execute arbitrary SQL commands via the macAddress element in a (1) getUploadPath or (2) getKBot SOAP request to service/kbot_service.php; the ID parameter to (3) userui/advisory_detail.php or (4) userui/ticket.php; and the (5) ORDER[] parameter to userui/ticket_list.php.

CVSS Metrics

Vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Access Vector
network
Access Cmplx
low
Auth
single
Confidentiality
partial
Integrity
partial
Availability
partial
Weaknesses
CWE-89

Metadata

Primary Vendor
DELL
Published
1/26/2014
Last Modified
4/11/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

dell : kace_k1000_systems_management_appliance_softwaredell : kace_k1000_systems_management_virtual_appliancedell : kace_k1000_systems_management_appliancedell : kace_k1100s_systems_management_appliancedell : kace_k1200s_systems_management_appliance

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2014-1671 | UNKNOWN Severity | CVEDatabase.com | CVEDatabase.com