First published: Sat Jun 02 2018(Updated: )
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 13 of 46).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Quest Disk Backup | <4.0.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11155 is a vulnerability that allows command injection in Quest DR Series Disk Backup software before version 4.0.3.1.
The severity of CVE-2018-11155 is high with a CVSS score of 8.8.
CVE-2018-11155 affects Quest DR Series Disk Backup software before version 4.0.3.1, allowing command injection.
Yes, updating Quest DR Series Disk Backup software to version 4.0.3.1 or later will fix the CVE-2018-11155 vulnerability.
Yes, you can find more information about CVE-2018-11155 in the following references: [1](http://packetstormsecurity.com/files/148003/Quest-DR-Series-Disk-Backup-Software-4.0.3-Code-Execution.html), [2](http://seclists.org/fulldisclosure/2018/May/71), [3](https://www.coresecurity.com/advisories/quest-dr-series-disk-backup-multiple-vulnerabilities).