10
CVSSv2

CVE-2008-0244

Published: 12/01/2008 Updated: 15/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

SAP MaxDB 7.6.03 build 007 and previous versions allows remote malicious users to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo and other unspecified commands, which are executed when MaxDB invokes cons.exe.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sap maxdb

Exploits

####################################################################### Luigi Auriemma Application: SAP MaxDB wwwsdnsapcom/irj/sdn/maxdb wwwsapcom Versions: <= 7603 build 007 Platforms: Windows, Linux and Solaris Bug: pre-auth remote commands execut ...

Github Repositories

This is a functional proof of concept program to aid in exploiting systems vulnerable to CVE 2008-0244. This vulnerability specifically relates to issues in how the SAP MaxDB protocol handles specially crafted packets. It is possible to execute system level commands remotely.

sapmdbret This is a functional exploit proof of concept program to aid in exploiting systems vulnerable to CVE 2008-0244 This vulnerability specifically relates to issues in how the SAP MaxDB protocol handles specially crafted packets It is possible to execute system level commands remotely Please note that some values (such as attacker IP, and the commands being executed)