CVE-2018-11173: OS Command Injection
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 31 of 46).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11173?
The severity of CVE-2018-11173 is high with a CVSS score of 8.8.
What is the vulnerability description of CVE-2018-11173?
CVE-2018-11173 is a command injection vulnerability in Quest DR Series Disk Backup software version before 4.0.3.1, allowing an attacker to execute arbitrary commands.
What software versions are affected by CVE-2018-11173?
Quest DR Series Disk Backup software versions up to and excluding 4.0.3.1 are affected by CVE-2018-11173.
How can I fix CVE-2018-11173?
Upgrade to Quest DR Series Disk Backup software version 4.0.3.1 or later to fix CVE-2018-11173.
What are the references for CVE-2018-11173?
For more information about CVE-2018-11173, refer to the following references: [PacketStormSecurity](http://packetstormsecurity.com/files/148003/Quest-DR-Series-Disk-Backup-Software-4.0.3-Code-Execution.html), [SecLists](http://seclists.org/fulldisclosure/2018/May/71), [Core Security](https://www.coresecurity.com/advisories/quest-dr-series-disk-backup-multiple-vulnerabilities)