CVE-2011-3340

ATCOM Netvolution 2.5.8 - SQL Injection via Referer HTTP Header

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-3340. PoCs published by Patroklos Argyroudis.

AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in Netvolution 2.5.8, where unsanitized user input in the 'Referer' header can be exploited to manipulate SQL queries. It includes a basic example payload but lacks executable exploit code.

Description

SQL injection vulnerability in ATCOM Netvolution 2.5.8 ASP allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Patroklos Argyroudis · textwebappsphp
https://www.exploit-db.com/exploits/36200

The provided text describes an SQL injection vulnerability in Netvolution 2.5.8, where unsanitized user input in the 'Referer' header can be exploited to manipulate SQL queries. It includes a basic example payload but lacks executable exploit code.

Classification
Writeup 80%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Netvolution 2.5.8
No auth needed
Prerequisites: Ability to send crafted HTTP requests to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/519984/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46255

Scores

EPSS 0.0204
EPSS Percentile 78.7%

Details

CWE
CWE-89
Status published
Products (1)
atcom/netvolution 2.5.6
Published Oct 21, 2011
Tracked Since Feb 18, 2026