KACE System Management Appliance CVE-2018-11138 Command Injection Vulnerability

description-logoDescription

The \'/common/download_agent_installer.php\' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.

affected-products-logoAffected Applications

KACE System Management Appliance

CVE References

CVE-2018-11138