CVE-2008-0244
SAP Maxdb < 7.6.3_build_007 - Improper Input Validation
Title source: ruleDescription
SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo and other unspecified commands, which are executed when MaxDB invokes cons.exe.
Exploits (2)
exploitdb
WRITEUP
VERIFIED
by Luigi Auriemma · textremotemultiple
https://www.exploit-db.com/exploits/4877
metasploit
WORKING POC
by MC · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/maxdb/maxdb_cons_exec.rb
References (9)
Scores
EPSS
0.8982
EPSS Percentile
99.6%
Details
CWE
CWE-20
Status
published
Products (1)
sap/maxdb
< 7.6.3_build_007
Published
Jan 12, 2008
Tracked Since
Feb 18, 2026