The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
        
        
        
 id: CVE-2018-11138
info:
  name: Quest KACE System Management Appliance 8.0.318 - Remote Code Execu
...