CVE-2018-11171: OS Command Injection
Published Jun 1, 2018
·Updated
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 29 of 46).
Affected Software
1 affected component
Quest Disk Backup<4.0.3.1
Event History
Jun 1, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-11171?
The severity of CVE-2018-11171 is high with a CVSS score of 8.8.
2
What is the vulnerability type of CVE-2018-11171?
CVE-2018-11171 is a command injection vulnerability.
3
Which software versions are affected by CVE-2018-11171?
Quest DR Series Disk Backup software versions before 4.0.3.1 are affected by CVE-2018-11171.
4
How can I fix CVE-2018-11171?
To fix CVE-2018-11171, update your Quest DR Series Disk Backup software to version 4.0.3.1 or later.
5
Are there any references for CVE-2018-11171?
Yes, here are some references for CVE-2018-11171: [link1](http://packetstormsecurity.com/files/148003/Quest-DR-Series-Disk-Backup-Software-4.0.3-Code-Execution.html), [link2](http://seclists.org/fulldisclosure/2018/May/71), [link3](https://www.coresecurity.com/advisories/quest-dr-series-disk-backup-multiple-vulnerabilities).