CVE-2018-11152: OS Command Injection
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 10 of 46).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11152?
The severity of CVE-2018-11152 is high with a severity value of 8.8.
What software version is affected by CVE-2018-11152?
Quest DR Series Disk Backup software version before 4.0.3.1 is affected by CVE-2018-11152.
What is the vulnerability description of CVE-2018-11152?
CVE-2018-11152 is a command injection vulnerability in Quest DR Series Disk Backup software version before 4.0.3.1.
How can I mitigate CVE-2018-11152?
To mitigate CVE-2018-11152, update to Quest DR Series Disk Backup software version 4.0.3.1 or later.
Are there any references for CVE-2018-11152?
Yes, here are some references for CVE-2018-11152: [1] http://packetstormsecurity.com/files/148003/Quest-DR-Series-Disk-Backup-Software-4.0.3-Code-Execution.html, [2] http://seclists.org/fulldisclosure/2018/May/71, [3] https://www.coresecurity.com/advisories/quest-dr-series-disk-backup-multiple-vulnerabilities