CVE-2016-20096 Details
Description
Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the name parameter in a POST request to the login endpoint. Attackers can inject malicious SQL through the login form and retrieve injected query results from a subsequent session request, enabling extraction of plaintext credentials and other database content with DBA-level privileges.
A SQL injection vulnerability has been identified in Linknat VOS3000 and VOS2009 applications, all versions prior to 2.1.2.0. This vulnerability allows remote attackers to execute arbitrary SQL commands by manipulating the name parameter in a POST request to the login endpoint. The injection can be exploited to retrieve query results in the same session, potentially leading to the extraction of plaintext credentials and other database information with DBA-level privileges.
Users are advised to upgrade to Linknat VOS3000 or VOS2009 version 2.1.2.4.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 21, 2026CISA-ADP
Assessed Jul 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Linknat VOS3000 | 2.1.1.5 2.1.1.8 2.1.2.0 |
CPE
Remediation
| |
| Linknat VOS2009 | 2.1.1.5 2.1.1.8 2.1.2.0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Modified | CISA-ADP |
| Jul 21, 2026 | New CVE Received | [email protected] |
Volerion