7.5
CVSSv2

CVE-2008-6853

Published: 07/07/2009 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in modules/poll/index.php in AIST NetCat 3.0 and 3.12 allows remote malicious users to execute arbitrary SQL commands via the PollID parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

netcat netcat 3.0

netcat netcat 3.12

Exploits

<? /* AIST NetCat Blind SQL Injection exploit by s4avrd0w [s4avrd0w@p0cru] Versions affected <= 312 More info: wwwnetcatru/ * tested on version 30, 312 usage: # /NetCat_blind_SQL_exploitphp -s=NetCat_server -u=User_ID The options are required: -u The user identifier (number in table) -s Target for exploiting ...