CVE-2018-11139: OS Command Injection
The '/common/ajaxemailconnectiontest.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticated user and can be abused to execute arbitrary commands on the system. This script is vulnerable to command injection via the unsanitized user input 'TESTSERVER' sent to the script via the POST method.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11139?
CVE-2018-11139 is considered to have a high severity due to its potential for arbitrary command execution.
How do I fix CVE-2018-11139?
To fix CVE-2018-11139, ensure that the affected Quest KACE System Management Appliance is updated to a patched version that sanitizes user inputs.
Who is affected by CVE-2018-11139?
Any authenticated user of the Quest KACE System Management Appliance version 8.0.318 is potentially affected by CVE-2018-11139.
What types of attacks can be performed using CVE-2018-11139?
CVE-2018-11139 allows attackers to perform command injection attacks by exploiting the unsanitized input in the '/common/ajax_email_connection_test.php' script.
Is CVE-2018-11139 a localized vulnerability?
CVE-2018-11139 is not localized and can be exploited by any authenticated user irrespective of their geographical location.