Quest NetVault Backup Server < 11.4.5 Process Manager Service SQL Injection Remote Code Execution Vulnerability (ZDI-17-982)
High Nessus Plugin ID 119681
SynopsisThe remote backup server is affected by an SQL injection remote code execution vulnerability.
DescriptionThe version of Quest NetVault Backup Server running on the remote host is prior to 11.4.5. It is, therefore, affected by an SQL injection (SQLi) remote code execution vulnerability in the process manager server due to improper validation of user-supplied input. An unauthenticated, remote attacker can exploit this to inject or manipulate SQL queries in the back-end database, resulting in the disclosure or manipulation of arbitrary data and the execution of arbitrary code.
Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
SolutionUpgrade to Quest NetVault Backup Server 11.4.5 or later.