CVE-2018-11138

Quest KACE System Management Appliance Remote Command Execution Vulnerability

Description

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance is accessible by anonymous users and can be abused to perform remote code execution.

Severity: CRITICAL

CVSS Score: 9.8

Vendor: Quest

Product: KACE System Management Appliance

Loading CVE details...