vendor:
Navicat
by:
Kevin McGuigan
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Navicat
Affected Version From: 12.0.26
Affected Version To: 12.0.27
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 32-bit
2018
Navicat < 12.0.27 Oracle Connection Overflow
Navicat is vulnerable to a buffer overflow when a user creates a new Oracle connection and pastes a specially crafted string into the host field. This can be exploited to execute arbitrary code by an attacker.
Mitigation:
Upgrade to the latest version of Navicat (12.0.27) to patch the vulnerability.