Skip to content
Noroxi

netsweeper records

19 published records for vendor netsweeper.

All records

19 records
  • CVE-2020-13167
    67This week

    Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) la

    CriticalCVSS 9.8WeaponizedEPSS 95%

    netsweeper · netsweeperMay 19, 2020

  • CVE-2014-9618
    61This week

    The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass aut

    CriticalCVSS 9.8Proof of conceptEPSS 73%

    netsweeper · netsweeperSep 19, 2017

  • CVE-2014-9614
    60This week

    The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attac

    CriticalCVSS 9.8Proof of conceptEPSS 69%

    netsweeper · netsweeperFeb 19, 2020

  • Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to webadmi

    CriticalCVSS 9.8Proof of conceptEPSS 13%

    netsweeper · netsweeperSep 19, 2017

  • Unspecified vulnerability in the WebAdmin Portal in Netsweeper has unknown impact and attack vectors, a different vulnerability than CVE-201

    CriticalCVSS 10.0Proof of conceptEPSS 3%

    netsweeper · netsweeperJul 9, 2012

  • SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allo

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    netsweeper · netsweeperFeb 19, 2020

  • Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL commands via the (1) l

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    netsweeper · netsweeperFeb 19, 2020

  • CVE-2014-9605
    38Monitor

    WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and crea

    CriticalCVSS 9.4Proof of conceptEPSS 4%

    netsweeper · netsweeperSep 4, 2015

  • CVE-2014-9616
    31Monitor

    Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to obtain sensitive information by making a req

    HighCVSS 7.5No exploitEPSS 2%

    netsweeper · netsweeperSep 19, 2017

  • CVE-2014-9619
    30Monitor

    Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and

    HighCVSS 7.2Proof of conceptEPSS 7%

    netsweeper · netsweeperSep 19, 2017

  • CVE-2012-2447
    27Monitor

    Cross-site request forgery (CSRF) vulnerability in accountmgr/adminupdate.php in the WebAdmin Portal in Netsweeper allows remote attackers t

    MediumCVSS 6.8No exploitEPSS 1%

    netsweeper · netsweeperJul 9, 2012

  • CVE-2014-9617
    26Monitor

    Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbi

    MediumCVSS 6.1Proof of conceptEPSS 8%

    netsweeper · netsweeperFeb 19, 2020

  • CVE-2014-9609
    25Monitor

    Directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before

    MediumCVSS 5.3Proof of conceptEPSS 13%

    netsweeper · netsweeperFeb 19, 2020

  • CVE-2014-9607
    25Monitor

    Cross-site scripting (XSS) vulnerability in remotereporter/load_logfiles.php in Netsweeper 4.0.3 and 4.0.4 allows remote attackers to inject

    MediumCVSS 6.1Proof of conceptEPSS 5%

    netsweeper · netsweeperFeb 19, 2020

  • CVE-2014-9608
    25Monitor

    Cross-site scripting (XSS) vulnerability in webadmin/policy/group_table_ajax.php/ in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x

    MediumCVSS 6.1Proof of conceptEPSS 5%

    netsweeper · netsweeperFeb 19, 2020

  • CVE-2014-9606
    25Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allow remote att

    MediumCVSS 6.1Proof of conceptEPSS 4%

    netsweeper · netsweeperFeb 19, 2020

  • CVE-2014-9615
    25Monitor

    Cross-site scripting (XSS) vulnerability in Netsweeper 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the url para

    MediumCVSS 6.1Proof of conceptEPSS 4%

    netsweeper · netsweeperFeb 19, 2020

  • CVE-2014-9610
    22Monitor

    Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and remove IP addresse

    MediumCVSS 5.3Proof of conceptEPSS 4%

    netsweeper · netsweeperSep 19, 2017

  • CVE-2012-2446
    17Monitor

    Cross-site scripting (XSS) vulnerability in tools/local_lookup.php in the WebAdmin Portal in Netsweeper allows remote attackers to inject ar

    MediumCVSS 4.3No exploitEPSS 1%

    netsweeper · netsweeperJul 9, 2012