CVE-2008-5729

AIST NetCat <3.12 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) form and (2) control parameters to FCKeditor/neditor.php, and the (3) path parameter to admin/siteinfo/iframe.inc.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by s4avrd0w · textwebappsphp
https://www.exploit-db.com/exploits/7560

Scores

EPSS 0.0313
EPSS Percentile 86.7%

Classification

CWE
CWE-79
Status published

Affected Products (9)

netcat/netcat < 3.12
netcat/netcat
netcat/netcat
netcat/netcat
netcat/netcat
netcat/netcat
netcat/netcat
netcat/netcat
n/a/n/a

Timeline

Published Dec 26, 2008
Tracked Since Feb 18, 2026