CVE-2018-11172: OS Command Injection
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 30 of 46).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11172?
The severity of CVE-2018-11172 is high with a severity value of 8.8.
What is CVE-2018-11172?
CVE-2018-11172 is a vulnerability in Quest DR Series Disk Backup software version before 4.0.3.1 that allows command injection.
How does CVE-2018-11172 affect Quest DR Series Disk Backup software?
CVE-2018-11172 affects Quest DR Series Disk Backup software version before 4.0.3.1 by allowing command injection.
How can I fix CVE-2018-11172?
To fix CVE-2018-11172, update your Quest DR Series Disk Backup software to version 4.0.3.1 or later.
Where can I find more information about CVE-2018-11172?
You can find more information about CVE-2018-11172 at the following references: [1] http://packetstormsecurity.com/files/148003/Quest-DR-Series-Disk-Backup-Software-4.0.3-Code-Execution.html [2] http://seclists.org/fulldisclosure/2018/May/71 [3] https://www.coresecurity.com/advisories/quest-dr-series-disk-backup-multiple-vulnerabilities