cvedb.io
CVE-2018-11139
HIGH · CVSS 8.8
EPSS exploitation probability: 0%
Published 2018-05-31T18:29:00.590 · Last modified 2026-06-17T01:35:19.627

Summary

The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticated user and can be abused to execute arbitrary commands on the system. This script is vulnerable to command injection via the unsanitized user input 'TEST_SERVER' sent to the script via the POST method.

Affected products

quest — kace_system_management_appliance

Does this affect you?

Add your gear to cvedb and we'll alert you only when quest ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.