CVE-2008-0244

SAP Maxdb < 7.6.3_build_007 - Improper Input Validation

Title source: rule

Description

SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo and other unspecified commands, which are executed when MaxDB invokes cons.exe.

Exploits (2)

exploitdb WRITEUP VERIFIED
by Luigi Auriemma · textremotemultiple
https://www.exploit-db.com/exploits/4877
metasploit WORKING POC
by MC · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/maxdb/maxdb_cons_exec.rb

Scores

EPSS 0.8982
EPSS Percentile 99.6%

Details

CWE
CWE-20
Status published
Products (1)
sap/maxdb < 7.6.3_build_007
Published Jan 12, 2008
Tracked Since Feb 18, 2026