CVE-2018-11139

CVE-2018-11139

The ‘/common/ajax_email_connection_test.php’ script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticated user and can be abused to execute arbitrary commands on the system. This script is vulnerable to command injection via the unsanitized user input ‘TEST_SERVER’ sent to the script via the POST method.

Source: CVE-2018-11139

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다