CVE-2018-11136: SQL Injection
Published May 31, 2018
·Updated
The 'orgID' parameter received by the '/common/downloadagentinstaller.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injection (in particular, a blind time-based type).
Affected Software
1 affected component
Quest KACE System Management Appliance=8.0.318
Event History
May 31, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-11136?
CVE-2018-11136 is classified as a medium severity vulnerability due to its potential impact from SQL injection attacks.
2
How do I fix CVE-2018-11136?
To fix CVE-2018-11136, sanitize the 'orgID' parameter input in the '/common/download_agent_installer.php' script.
3
What type of vulnerability is CVE-2018-11136?
CVE-2018-11136 is an SQL injection vulnerability, specifically a blind time-based type.
4
Which version of Quest KACE System Management Appliance is affected by CVE-2018-11136?
CVE-2018-11136 affects Quest KACE System Management Appliance version 8.0.318.
5
What are the potential consequences of exploiting CVE-2018-11136?
Exploiting CVE-2018-11136 can allow attackers to perform unauthorized SQL queries, potentially exposing sensitive data.