NetCat records
11 published records for vendor netcat.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 9.1%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-204 Observable Response Discrepancy1
- CWE-20 Improper Input Validation1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
48Plan | CVE-2004-1317Weaponized | Stack-based buffer overflow in doexec.c in Netcat for Windows 1.1, when running with the -e option, allows remote attackers to execute arbitnetcat · netcat | High7.5 | — | 60.4% | Dec 27, 2004 |
31Monitor | CVE-2008-5730Proof of concept | Multiple CRLF injection vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to have an unknown impact via unspecified vecnetcat · netcat · CWE-20 | High7.5 | — | 2.2% | Dec 26, 2008 |
30Monitor | CVE-2008-6853Proof of concept | SQL injection vulnerability in modules/poll/index.php in AIST NetCat 3.0 and 3.12 allows remote attackers to execute arbitrary SQL commands netcat · netcat · CWE-89 | High7.5 | — | 1.0% | Jul 7, 2009 |
28Monitor | CVE-2008-5727Proof of concept | SQL injection vulnerability in modules/auth/password_recovery.php in AIST NetCat 3.12 and earlier, when magic_quotes_gpc is disabled, allowsnetcat · netcat · CWE-89 | Medium6.8 | — | 1.9% | Dec 26, 2008 |
27Monitor | CVE-2024-8651No exploit | Netcat CMS: user enumerationnetcat · netcat content management system · CWE-204 | Medium6.9 | — | 0.4% | Sep 19, 2024 |
23Monitor | CVE-2024-8653No exploit | Netcat CMS: multiple reflected cross-site scripting vulnerabilities in netshop modulenetcat · netcat content management system · CWE-79 | Medium5.9 | — | 0.3% | Sep 19, 2024 |
23Monitor | CVE-2024-8652No exploit | Netcat CMS: reflected cross-site scripting in openstat modulenetcat · netcat content management system · CWE-79 | Medium5.9 | — | 0.3% | Sep 19, 2024 |
21Monitor | CVE-2015-2214No exploit | NetCat 5.01 and earlier allows remote attackers to obtain the installation path via the redirect_url parameter to netshop/post.php.netcat · netcat · CWE-200 | Medium5.0 | — | 2.4% | Mar 5, 2015 |
21Monitor | CVE-2008-5728Proof of concept | Multiple directory traversal vulnerabilities in AIST NetCat 3.12 and earlier, when magic_quotes_gpc is disabled and register_globals is enabnetcat · netcat · CWE-22 | Medium5.1 | — | 2.0% | Dec 26, 2008 |
17Monitor | CVE-2008-5742Proof of concept | Multiple open redirect vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to redirect users to arbitrary web sites and cnetcat · netcat · CWE-59 | Medium4.0 | — | 2.0% | Dec 26, 2008 |
17Monitor | CVE-2008-5729Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to inject arbitrary web script ornetcat · netcat · CWE-79 | Medium4.3 | — | 1.4% | Dec 26, 2008 |
- CVE-2004-131748Plan
Stack-based buffer overflow in doexec.c in Netcat for Windows 1.1, when running with the -e option, allows remote attackers to execute arbit
HighCVSS 7.5WeaponizedEPSS 60%netcat · netcatDec 27, 2004
- CVE-2008-573031Monitor
Multiple CRLF injection vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to have an unknown impact via unspecified vec
HighCVSS 7.5Proof of conceptEPSS 2%netcat · netcatDec 26, 2008
- CVE-2008-685330Monitor
SQL injection vulnerability in modules/poll/index.php in AIST NetCat 3.0 and 3.12 allows remote attackers to execute arbitrary SQL commands
HighCVSS 7.5Proof of conceptEPSS 1%netcat · netcatJul 7, 2009
- CVE-2008-572728Monitor
SQL injection vulnerability in modules/auth/password_recovery.php in AIST NetCat 3.12 and earlier, when magic_quotes_gpc is disabled, allows
MediumCVSS 6.8Proof of conceptEPSS 2%netcat · netcatDec 26, 2008
- CVE-2024-865127Monitor
Netcat CMS: user enumeration
MediumCVSS 6.9No exploitEPSS 0%netcat · netcat content management systemSep 19, 2024
- CVE-2024-865323Monitor
Netcat CMS: multiple reflected cross-site scripting vulnerabilities in netshop module
MediumCVSS 5.9No exploitEPSS 0%netcat · netcat content management systemSep 19, 2024
- CVE-2024-865223Monitor
Netcat CMS: reflected cross-site scripting in openstat module
MediumCVSS 5.9No exploitEPSS 0%netcat · netcat content management systemSep 19, 2024
- CVE-2015-221421Monitor
NetCat 5.01 and earlier allows remote attackers to obtain the installation path via the redirect_url parameter to netshop/post.php.
MediumCVSS 5.0No exploitEPSS 2%netcat · netcatMar 5, 2015
- CVE-2008-572821Monitor
Multiple directory traversal vulnerabilities in AIST NetCat 3.12 and earlier, when magic_quotes_gpc is disabled and register_globals is enab
MediumCVSS 5.1Proof of conceptEPSS 2%netcat · netcatDec 26, 2008
- CVE-2008-574217Monitor
Multiple open redirect vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to redirect users to arbitrary web sites and c
MediumCVSS 4.0Proof of conceptEPSS 2%netcat · netcatDec 26, 2008
- CVE-2008-572917Monitor
Multiple cross-site scripting (XSS) vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to inject arbitrary web script or
MediumCVSS 4.3Proof of conceptEPSS 1%netcat · netcatDec 26, 2008