6.8
CVSSv2

CVE-2008-5727

Published: 26/12/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in modules/auth/password_recovery.php in AIST NetCat 3.12 and previous versions, when magic_quotes_gpc is disabled, allows remote malicious users to execute arbitrary SQL commands via the query string.

Vulnerable Product Search on Vulmon Subscribe to Product

netcat netcat 2.0

netcat netcat 1.1

netcat netcat 3.0

netcat netcat 2.4

netcat netcat 2.3

netcat netcat

netcat netcat 2.2

netcat netcat 2.1

Exploits

<? /* NetCat Blind SQL Injection exploit by s4avrd0w [s4avrd0w@p0cru] Versions affected 312 More info: wwwnetcatru/ * tested on version 312 usage: # /NetCat_blind_SQL_exploitphp -s=NetCat_server -u=User_ID The options are required: -u The user identifier (number in table) -s Target for exploiting example: # / ...