{"id":27353,"date":"2022-07-22T01:28:11","date_gmt":"2022-07-21T21:28:11","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/167779\/kite120216100-unquotedpath.txt"},"modified":"2022-07-22T11:36:20","modified_gmt":"2022-07-22T07:06:20","slug":"kite-1-2021-610-0-unquoted-service-path","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/kite-1-2021-610-0-unquoted-service-path\/","title":{"rendered":"Kite 1.2021.610.0 Unquoted Service Path"},"content":{"rendered":"<dl id=\"F167779\" class=\"file first\">\n<dt dir=\"ltr\"><a class=\"ico text-plain\" title=\"Size: 0.7 KB\" href=\"https:\/\/packetstormsecurity.com\/files\/download\/167779\/kite120216100-unquotedpath.txt\" target=\"_blank\" rel=\"noopener\"><strong>Kite 1.2021.610.0 Unquoted Service Path<\/strong><\/a><\/dt>\n<dd class=\"datetime\" dir=\"ltr\">Posted <a title=\"20:28:36 UTC\" href=\"https:\/\/packetstormsecurity.com\/files\/date\/2022-07-21\/\" target=\"_blank\" rel=\"noopener\">Jul 21, 2022<\/a><\/dd>\n<dd class=\"refer\" dir=\"ltr\">Authored by <a class=\"person\" href=\"https:\/\/packetstormsecurity.com\/files\/author\/16383\/\" target=\"_blank\" rel=\"noopener\">Ghaleb Al-otaibi<\/a><\/dd>\n<dd class=\"detail\" dir=\"ltr\">Kite version 1.2021.610.0 suffers from an unquoted service path vulnerability.<\/dd>\n<dd class=\"tags\" dir=\"ltr\">tags | <a href=\"https:\/\/packetstormsecurity.com\/files\/tags\/exploit\" target=\"_blank\" rel=\"noopener\">exploit<\/a><\/dd>\n<dd class=\"md5\" dir=\"ltr\">SHA-256 | <code>f6c26ab826fa44ce94b3128d1027703b3451aafa787d124ff97ae6903c5c30b1<\/code><\/dd>\n<dd class=\"act-links\" dir=\"ltr\"><a title=\"Size: 0.7 KB\" href=\"https:\/\/packetstormsecurity.com\/files\/download\/167779\/kite120216100-unquotedpath.txt\" rel=\"nofollow noopener\" target=\"_blank\">Download<\/a> | <a class=\"fav\" href=\"https:\/\/packetstormsecurity.com\/files\/favorite\/167779\/\" rel=\"nofollow noopener\" target=\"_blank\">Favorite<\/a> | <a href=\"https:\/\/packetstormsecurity.com\/files\/167779\/Kite-1.2021.610.0-Unquoted-Service-Path.html\" target=\"_blank\" rel=\"noopener\">View<\/a><\/dd>\n<\/dl>\n<div class=\"src\" dir=\"ltr\">\n<pre><code># Exploit Title: Kite 1.2021.610.0 - Unquoted Service Path\r\n# Date: 2020-11-6\r\n# Exploit Author: Ghaleb Al-otaibi\r\n# Vendor Homepage: https:\/\/www.kite.com\/\r\n# Version: Version 4.2.0.1 U1\r\n# Tested on: Microsoft Windows 10 Pro - 10.0.19044 N\/A Build 19044\r\n# CVE : NA<\/code><\/pre>\n<p># Service info:<br \/>\nC:\\Windows\\system32\\cmd.exe&gt;sc qc KiteService<br \/>\n[SC] QueryServiceConfig SUCCESS<\/p>\n<pre><code><\/code><\/pre>\n<p>SERVICE_NAME: KiteService<br \/>\nTYPE : 10 WIN32_OWN_PROCESS<br \/>\nSTART_TYPE : 2 AUTO_START<br \/>\nERROR_CONTROL : 0 IGNORE<br \/>\nBINARY_PATH_NAME : C:\\Program Files\\Kite\\KiteService.exe<br \/>\nLOAD_ORDER_GROUP :<br \/>\nTAG : 0<br \/>\nDISPLAY_NAME : KiteService<br \/>\nDEPENDENCIES :<br \/>\nSERVICE_START_NAME : LocalSystem<\/p>\n<pre><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre><code><\/code><\/pre>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Kite 1.2021.610.0 Unquoted Service Path Posted Jul 21, 2022 Authored by Ghaleb Al-otaibi Kite version 1.2021.610.0 suffers from an unquoted service path vulnerability. tags | exploit SHA-256 | f6c26ab826fa44ce94b3128d1027703b3451aafa787d124ff97ae6903c5c30b1 Download | Favorite | View # Exploit Title: Kite 1.2021.610.0 &#8211; Unquoted Service Path # Date: 2020-11-6 # Exploit Author: Ghaleb Al-otaibi # Vendor Homepage: https:\/\/www.kite.com\/ &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-27353","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/27353","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=27353"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/27353\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=27353"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=27353"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=27353"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}