CVE-2024-38887
Critical · CVSS 9.8Caterease — OS Command Injection via excessive database privileges (CWE-78)
- CVSS
- 9.8
- nvd
- EPSS
- 1.68%
- 74th pct
- KEV
- No
- Class
- other
- CWE-78, CWE-78
Description
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating system from the database due to the execution of commands with unnecessary privileges.
Search profile — drives PoC discovery
Symbols xp_cmdshellSQL InjectionCommand Injectiondatabase privilegesos command executionCatereaseMSSQL
Keywords CVE-2024-38887Catereasecommand injectionSQL injectionOS command injectiondatabase privilege escalationHorizon Business ServicesCaterease 16.0.1Caterease 24.0.1packetstorm 179892
Versions: 16.0.1.1663 through 24.0.1.2405
Ranked PoCs (29) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
- ★ 10
- ★ 139Don-No7/Hack-SQL needs reviewgh_search
- ★ 19OSTEsayed/OSTE-Vulnerable-Web-Application needs reviewgh_search · PHP
- ★ 17HlaingPhyoAung/sqlmap needs reviewgh_search
- ★ 4BoutadjineAlaa/Waffles needs reviewgh_search · Python
- ★ 2DeaDHackS/SQLSploit needs reviewgh_search · Shell
- ★ 2kilkat/diss needs reviewgh_search · JavaScript
- ★ 1AlinFe/web-simple-vulnerabilities-scan needs reviewgh_search · Python
- ★ 1AmritanshTiwari2160/Vulnerability-Assessment-Web-App needs reviewgh_search · Python
- ★ 1
- ★ 1
- ★ 1utkuonursahin/injections needs reviewgh_search · Java
- ★ 1
- ★ 0
- ★ 0BatuDursun/WebZaafiyetleriUygulama needs reviewgh_search · PHP
- ★ 0
- ★ 0
- ★ 0MuhammadIsamuTaqiyAli/Contrasting-Injection-Defenses-OS-Command-vs.-SQL-Mitigation-NoSQL-LDAP-XML-Risks needs reviewgh_search · Python
- ★ 0
- ★ 0gh_search · PHP
- ★ 0
- ★ 0duvaninho/especializacion-seguridad needs reviewgh_search
- ★ 0fkie-cad/nvd-json-data-feeds needs reviewtrickest
- ★ 0infosectalha/bWAPP-vulnerability-Assessment needs reviewgh_search
- ★ 0mohamedtb20/OS-command-injection needs reviewgh_search
- ★ 0
- ★ 0solenebutruille/CTF-numbers-map needs reviewgh_search · Java
- ★ 0
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T00:30:39.000Z