CVE-2018-11188: OS Command Injection
Published Jun 1, 2018
·Updated
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 46 of 46).
Affected Software
1 affected component
Quest Disk Backup<4.0.3.1
Event History
Jun 1, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-11188?
CVE-2018-11188 is a vulnerability found in Quest DR Series Disk Backup software version before 4.0.3.1 that allows command injection.
2
What is the severity of CVE-2018-11188?
The severity of CVE-2018-11188 is high, with a severity value of 8.8.
3
How does CVE-2018-11188 affect Quest DR Series Disk Backup software?
CVE-2018-11188 affects Quest DR Series Disk Backup software version before 4.0.3.1 by allowing command injection.
4
What is the Common Weakness Enumeration (CWE) associated with CVE-2018-11188?
The CWE associated with CVE-2018-11188 are CWE-77 (Improper Neutralization of Special Elements used in a Command) and CWE-78 (Improper Neutralization of Special Elements used in an OS Command).
5
How can I fix the CVE-2018-11188 vulnerability?
To fix the CVE-2018-11188 vulnerability, it is recommended to update Quest DR Series Disk Backup software to version 4.0.3.1 or above.