← Vulnerability feed

Vulnerability record · CVE-2018-11137 · published 31 May 2018

CVE-2018-11137: Quest kace system management appliance path traversal vulnerability

Quest · Kace System Management Appliance

The 'checksum' parameter of the '/common/download_attachment.php' script in the Quest KACE System Management Appliance 8.0.318 can be abused to read arbitrary files with 'www' privileges via Directory Traversal. No administrator privileges are needed to execute this script.

6.5 CVSS 3.0 Medium EPSS 6.5% · top 6.5% CWE-22 · Path traversal
6.5CVSS 3.0 base score, v2 4.0
6.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The 'checksum' parameter of the '/common/download_attachment.php' script in the Quest KACE System Management Appliance 8.0.318 can be abused to read arbitrary files with 'www' privileges via Directory Traversal. No administrator privileges are needed to execute this script.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-11137 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-11138Quest KACE System Management Appliance unauthenticated OS command injectionThe download_agent_installer.php script in Quest KACE System Management Appliance 8.0.318 is reachable by anonymous users and passes input to the ope…KEVEPSS 92%analysed9.8CVE-2018-11136Quest kace system management appliance sql injection vulnerabilityThe 'orgID' parameter received by the '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is not sani…EPSS 1.4%9.8CVE-2018-11140Quest kace system management appliance sql injection vulnerabilityThe 'reportID' parameter received by the '/common/run_report.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, lead…EPSS 1.4%9.8CVE-2018-11141Quest kace system management appliance path traversal vulnerabilityThe 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE System Management Virtual Applianc…EPSS 2.0%8.8CVE-2018-11132Quest kace system management appliance os command injection vulnerabilityIn order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue that runs da…EPSS 18%8.8CVE-2018-11134Quest kace system management appliance weak password recovery vulnerabilityIn order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue managed tha…EPSS 3.0%8.8CVE-2018-11135Quest kace system management appliance prototype pollution vulnerabilityThe script '/adminui/error_details.php' in the Quest KACE System Management Appliance 8.0.318 allows authenticated users to conduct PHP object inject…EPSS 2.1%8.8CVE-2018-11139Quest kace system management appliance os command injection vulnerabilityThe '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticated user and…EPSS 43%

Source: NIST National Vulnerability Database (record CVE-2018-11137), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.