CVE-2008-5728
AIST NetCat <= 3.12 - Remote File Inclusion via Path Traversal
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5728. PoCs published by s4avrd0w.
AI-analyzed exploit summary This is a technical writeup detailing multiple vulnerabilities in NetCat CMS <= 3.12, including file inclusion, SQL injection, XSS, HTTP response splitting, and CRLF injection. It provides specific examples of vulnerable endpoints and required PHP configurations.
Description
Multiple directory traversal vulnerabilities in AIST NetCat 3.12 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the system parameter in modules/netshop/post.php; and the INCLUDE_FOLDER parameter in (2) auth.inc.php, (3) banner.inc.php, (4) blog.inc.php, and (5) forum.inc.php in modules/.
Exploits (1)
This is a technical writeup detailing multiple vulnerabilities in NetCat CMS <= 3.12, including file inclusion, SQL injection, XSS, HTTP response splitting, and CRLF injection. It provides specific examples of vulnerable endpoints and required PHP configurations.