CVE-2008-0244
SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo and other unspecified commands, which are executed when MaxDB invokes cons.exe.
- Affected products
- Sap Maxdb
- Sap Maxdb
- ≤ 7.6.3_build_007
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 80.3% (100th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2008-01-12
CVE-2008-0244 at NVD
8 known exploits for CVE-2008-0244
Proof-of-concept code and exploit modules indexed by Sploitus
SAP MaxDB Cons.exe Remote Command Injection
SAP MaxDB cons.exe Remote Command Injection
MySQL MaxDB cons.exe command injection
MySQL MaxDB cons.exe command injection
MySQL MaxDB cons.exe command injection
MySQL MaxDB cons.exe command injection
DSquare Exploit Pack: D2SEC_MAXDB
SAP MaxDB 7.6.03.07 - Remote Command Execution