Dell KACE K2000 Systems Deployment Appliance contains a flaw in the Task Processor component that is triggered when a web GUI administrator uses write access to the MySQL database. With a specially crafted 'insert' statement, an attacker can execute commands as 'root' on the underlying system, gaining full access to the device. Reproduction steps: