CVE-2008-5727

AIST NetCat <3.12 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in modules/auth/password_recovery.php in AIST NetCat 3.12 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the query string.

Exploits (1)

exploitdb WORKING POC VERIFIED
by s4avrd0w · phpwebappsphp
https://www.exploit-db.com/exploits/7559

Scores

EPSS 0.0034
EPSS Percentile 57.0%

Details

CWE
CWE-89
Status published
Products (8)
netcat/netcat 1.1
netcat/netcat 2.0
netcat/netcat 2.1
netcat/netcat 2.2
netcat/netcat 2.3
netcat/netcat 2.4
netcat/netcat 3.0
netcat/netcat < 3.12
Published Dec 26, 2008
Tracked Since Feb 18, 2026