CVE-2008-5742
Last modified
CVE-2008-5742 is a vulnerability of currently unknown severity. Multiple open redirect vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the redirect parameter in a logoff action to modules/auth/index.php or (2) the url parameter to modules/linkmanager/redirect.php. NOTE: this was reported within an "HTTP Response Splitting" section in the original disclosure.. EPSS estimates a 2.03% chance of exploitation in the next 30 days.
Description
Multiple open redirect vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the redirect parameter in a logoff action to modules/auth/index.php or (2) the url parameter to modules/linkmanager/redirect.php. NOTE: this was reported within an "HTTP Response Splitting" section in the original disclosure.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netcat | Netcat | <= 3.12 |
| Netcat | Netcat | 1.1 |
| Netcat | Netcat | 2.0 |
| Netcat | Netcat | 2.1 |
| Netcat | Netcat | 2.2 |
| Netcat | Netcat | 2.3 |
| Netcat | Netcat | 2.4 |
| Netcat | Netcat | 3.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-5742?
How severe is CVE-2008-5742?
How do I fix CVE-2008-5742?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-5734Cross-site scripting (XSS) vulnerability in WebMail Pro in I…
- CVE-2008-5735Stack-based buffer overflow in skin.c in CoolPlayer 2.17 thr…
- CVE-2008-5736Multiple unspecified vulnerabilities in FreeBSD 6 before 6.4…
- CVE-2008-5737SQL injection vulnerability in index.php in Nodstrum MySQL C…
- CVE-2008-5738Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers …
- CVE-2008-5739SQL injection vulnerability in evb/check_url.php in Pligg CM…
- CVE-2008-5743pdfjam creates the (1) pdf90, (2) pdfjoin, and (3) pdfnup fi…
- CVE-2008-5744Array index error in the dahdi/tor2.c driver in Zaptel (aka …
- CVE-2008-5745Integer overflow in quartz.dll in the DirectShow framework i…
- CVE-2008-5746Sun SNMP Management Agent (SUNWmasf) 1.4u2 through 1.5.4 all…
- CVE-2008-5747F-Prot 4.6.8 for GNU/Linux allows remote attackers to bypass…
- CVE-2008-5748Directory traversal vulnerability in plugins/spaw2/dialogs/d…8.1
Are you affected by CVE-2008-5742?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
