The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
https://www.exploit-db.com/exploits/44950/
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-11138