The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
id: CVE-2018-11138
info:
name: Quest KACE System Management Appliance 8.0.318 - Remote Code Execu
...