Vulnerabilities > Dell > Kace K2000 Systems Deployment Appliance
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2011-11-12 | CVE-2011-4436 | Cross-Site Scripting vulnerability in Dell Kace K2000 Systems Deployment Appliance Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface on the Dell KACE K2000 System Deployment Appliance allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 3.5 |
2011-11-12 | CVE-2011-4048 | Credentials Management vulnerability in Dell Kace K2000 Systems Deployment Appliance The Dell KACE K2000 System Deployment Appliance has a default username and password for the read-only reporting account, which makes it easier for remote attackers to obtain sensitive information from the database by leveraging the default credentials. | 4.3 |
2011-11-12 | CVE-2011-4047 | Code Injection vulnerability in Dell Kace K2000 Systems Deployment Appliance The Dell KACE K2000 System Deployment Appliance allows remote attackers to execute arbitrary commands by leveraging database write access. | 9.3 |
2011-11-12 | CVE-2011-4046 | Cryptographic Issues vulnerability in Dell Kace K2000 Systems Deployment Appliance The Dell KACE K2000 System Deployment Appliance stores the recovery account password in cleartext within a PHP script, which allows context-dependent attackers to obtain sensitive information by examining script source code. | 5.0 |
2011-04-10 | CVE-2011-1672 | Information Exposure vulnerability in Dell Kace K2000 Systems Deployment Appliance The Dell KACE K2000 Systems Deployment Appliance 3.3.36822 and earlier contains a peinst CIFS share, which allows remote attackers to obtain sensitive information by reading the (1) unattend.xml or (2) sysprep.inf file, as demonstrated by reading a password. | 5.0 |