Dell KACE K2000 System Deployment Appliance contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input to the 'log' parameter of the /settings_logs facility and the 'network_test_name' parameter of the /support_troubleshooting facility before returning it to the user.