SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Quest KACE System Management Appliance Command Injection

Category: WEB-ATTACKS      

The '/common/ajax_email_connection_test.php' script used to test the configured SMTP server is accessible by any authenticated user and can be abused to execute arbitrary commands on the system. This script is vulnerable to command injection via the unsanitized user input 'TEST_SERVER' sent to the script via POST method.


Relevant Information