NetCat kayıtları
netcat üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %9,1
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-204 Observable Response Discrepancy1
- CWE-20 Improper Input Validation1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
48Planlayın | CVE-2004-1317Silahlaştırılmış | Stack-based buffer overflow in doexec.c in Netcat for Windows 1.1, when running with the -e option, allows remote attackers to execute arbitnetcat · netcat | Yüksek7,5 | — | %60,4 | 27 Ara 2004 |
31İzleyin | CVE-2008-5730Kavram kanıtı | Multiple CRLF injection vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to have an unknown impact via unspecified vecnetcat · netcat · CWE-20 | Yüksek7,5 | — | %2,2 | 26 Ara 2008 |
30İzleyin | CVE-2008-6853Kavram kanıtı | SQL injection vulnerability in modules/poll/index.php in AIST NetCat 3.0 and 3.12 allows remote attackers to execute arbitrary SQL commands netcat · netcat · CWE-89 | Yüksek7,5 | — | %1,0 | 7 Tem 2009 |
28İzleyin | CVE-2008-5727Kavram kanıtı | SQL injection vulnerability in modules/auth/password_recovery.php in AIST NetCat 3.12 and earlier, when magic_quotes_gpc is disabled, allowsnetcat · netcat · CWE-89 | Orta6,8 | — | %1,9 | 26 Ara 2008 |
27İzleyin | CVE-2024-8651İstismar yok | Netcat CMS: user enumerationnetcat · netcat content management system · CWE-204 | Orta6,9 | — | %0,4 | 19 Eyl 2024 |
23İzleyin | CVE-2024-8653İstismar yok | Netcat CMS: multiple reflected cross-site scripting vulnerabilities in netshop modulenetcat · netcat content management system · CWE-79 | Orta5,9 | — | %0,3 | 19 Eyl 2024 |
23İzleyin | CVE-2024-8652İstismar yok | Netcat CMS: reflected cross-site scripting in openstat modulenetcat · netcat content management system · CWE-79 | Orta5,9 | — | %0,3 | 19 Eyl 2024 |
21İzleyin | CVE-2015-2214İstismar yok | NetCat 5.01 and earlier allows remote attackers to obtain the installation path via the redirect_url parameter to netshop/post.php.netcat · netcat · CWE-200 | Orta5,0 | — | %2,4 | 5 Mar 2015 |
21İzleyin | CVE-2008-5728Kavram kanıtı | Multiple directory traversal vulnerabilities in AIST NetCat 3.12 and earlier, when magic_quotes_gpc is disabled and register_globals is enabnetcat · netcat · CWE-22 | Orta5,1 | — | %2,0 | 26 Ara 2008 |
17İzleyin | CVE-2008-5742Kavram kanıtı | Multiple open redirect vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to redirect users to arbitrary web sites and cnetcat · netcat · CWE-59 | Orta4,0 | — | %2,0 | 26 Ara 2008 |
17İzleyin | CVE-2008-5729Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to inject arbitrary web script ornetcat · netcat · CWE-79 | Orta4,3 | — | %1,4 | 26 Ara 2008 |
- CVE-2004-131748Planlayın
Stack-based buffer overflow in doexec.c in Netcat for Windows 1.1, when running with the -e option, allows remote attackers to execute arbit
YüksekCVSS 7,5SilahlaştırılmışEPSS %60netcat · netcat27 Ara 2004
- CVE-2008-573031İzleyin
Multiple CRLF injection vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to have an unknown impact via unspecified vec
YüksekCVSS 7,5Kavram kanıtıEPSS %2netcat · netcat26 Ara 2008
- CVE-2008-685330İzleyin
SQL injection vulnerability in modules/poll/index.php in AIST NetCat 3.0 and 3.12 allows remote attackers to execute arbitrary SQL commands
YüksekCVSS 7,5Kavram kanıtıEPSS %1netcat · netcat7 Tem 2009
- CVE-2008-572728İzleyin
SQL injection vulnerability in modules/auth/password_recovery.php in AIST NetCat 3.12 and earlier, when magic_quotes_gpc is disabled, allows
OrtaCVSS 6,8Kavram kanıtıEPSS %2netcat · netcat26 Ara 2008
- CVE-2024-865127İzleyin
Netcat CMS: user enumeration
OrtaCVSS 6,9İstismar yokEPSS %0netcat · netcat content management system19 Eyl 2024
- CVE-2024-865323İzleyin
Netcat CMS: multiple reflected cross-site scripting vulnerabilities in netshop module
OrtaCVSS 5,9İstismar yokEPSS %0netcat · netcat content management system19 Eyl 2024
- CVE-2024-865223İzleyin
Netcat CMS: reflected cross-site scripting in openstat module
OrtaCVSS 5,9İstismar yokEPSS %0netcat · netcat content management system19 Eyl 2024
- CVE-2015-221421İzleyin
NetCat 5.01 and earlier allows remote attackers to obtain the installation path via the redirect_url parameter to netshop/post.php.
OrtaCVSS 5,0İstismar yokEPSS %2netcat · netcat5 Mar 2015
- CVE-2008-572821İzleyin
Multiple directory traversal vulnerabilities in AIST NetCat 3.12 and earlier, when magic_quotes_gpc is disabled and register_globals is enab
OrtaCVSS 5,1Kavram kanıtıEPSS %2netcat · netcat26 Ara 2008
- CVE-2008-574217İzleyin
Multiple open redirect vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to redirect users to arbitrary web sites and c
OrtaCVSS 4,0Kavram kanıtıEPSS %2netcat · netcat26 Ara 2008
- CVE-2008-572917İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to inject arbitrary web script or
OrtaCVSS 4,3Kavram kanıtıEPSS %1netcat · netcat26 Ara 2008