CVE-2016-20096
Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to e
CVSS
9.8
Crítico
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 21 jul 2026 · Última mod.: 21 jul 2026 · CWE-89
Sin historial EPSS suficiente todavía.
Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the name parameter in a POST request to the login endpoint. Attackers can inject malicious SQL through the login form and retrieve injected query results from a subsequent session request, enabling extraction of plaintext credentials and other database content with DBA-level privileges.
- packetstorm.newshttps://packetstorm.news/files/id/137159
- web.archive.orghttps://web.archive.org/web/20160601102456/http://www.wooyun.org/bugs/wooyun-2010-0145458
- www.linknat.comhttps://www.linknat.com/
- www.vulncheck.comhttps://www.vulncheck.com/advisories/linknat-vos3000-vos2009-sql-injection-via-login-jsp