CVE-2018-11140: SQL Injection
The 'reportID' parameter received by the '/common/runreport.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injection (in particular, an error-based type).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11140?
CVE-2018-11140 is classified as a high severity vulnerability due to the potential for exploitation through SQL injection.
How do I fix CVE-2018-11140?
To mitigate CVE-2018-11140, it is recommended to upgrade to a patched version of the Quest KACE System Management Appliance that addresses this SQL injection issue.
What is the impact of CVE-2018-11140?
The impact of CVE-2018-11140 includes the potential for unauthorized database access and manipulation through SQL injection.
Is CVE-2018-11140 exploitable remotely?
Yes, CVE-2018-11140 is remotely exploitable given that the vulnerable script is accessible over the network.
What versions are affected by CVE-2018-11140?
CVE-2018-11140 specifically affects the Quest KACE System Management Appliance version 8.0.318.