netsweeper records
19 published records for vendor netsweeper.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 5.3%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-287 Improper Authentication3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
19 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
67This week | CVE-2020-13167Weaponized | Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) lanetsweeper · netsweeper · CWE-78 | Critical9.8 | — | 95.0% | May 19, 2020 |
61This week | CVE-2014-9618Proof of concept | The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass autnetsweeper · netsweeper · CWE-287 | Critical9.8 | — | 72.7% | Sep 19, 2017 |
60This week | CVE-2014-9614Proof of concept | The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attacnetsweeper · netsweeper · CWE-798 | Critical9.8 | — | 68.7% | Feb 19, 2020 |
43Plan | CVE-2014-9611Proof of concept | Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to webadminetsweeper · netsweeper · CWE-287 | Critical9.8 | — | 12.7% | Sep 19, 2017 |
41Plan | CVE-2012-3859Proof of concept | Unspecified vulnerability in the WebAdmin Portal in Netsweeper has unknown impact and attack vectors, a different vulnerability than CVE-201netsweeper · netsweeper | Critical10.0 | — | 2.9% | Jul 9, 2012 |
40Plan | CVE-2014-9612Proof of concept | SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allonetsweeper · netsweeper · CWE-89 | Critical9.8 | — | 4.9% | Feb 19, 2020 |
40Plan | CVE-2014-9613Proof of concept | Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL commands via the (1) lnetsweeper · netsweeper · CWE-89 | Critical9.8 | — | 4.1% | Feb 19, 2020 |
38Monitor | CVE-2014-9605Proof of concept | WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and creanetsweeper · netsweeper · CWE-287 | Critical9.4 | — | 3.9% | Sep 4, 2015 |
31Monitor | CVE-2014-9616No exploit | Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to obtain sensitive information by making a reqnetsweeper · netsweeper · CWE-200 | High7.5 | — | 2.4% | Sep 19, 2017 |
30Monitor | CVE-2014-9619Proof of concept | Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and netsweeper · netsweeper · CWE-434 | High7.2 | — | 7.4% | Sep 19, 2017 |
27Monitor | CVE-2012-2447No exploit | Cross-site request forgery (CSRF) vulnerability in accountmgr/adminupdate.php in the WebAdmin Portal in Netsweeper allows remote attackers tnetsweeper · netsweeper · CWE-352 | Medium6.8 | — | 0.7% | Jul 9, 2012 |
26Monitor | CVE-2014-9617Proof of concept | Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbinetsweeper · netsweeper · CWE-601 | Medium6.1 | — | 8.0% | Feb 19, 2020 |
25Monitor | CVE-2014-9609Proof of concept | Directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x beforenetsweeper · netsweeper · CWE-22 | Medium5.3 | — | 12.6% | Feb 19, 2020 |
25Monitor | CVE-2014-9607Proof of concept | Cross-site scripting (XSS) vulnerability in remotereporter/load_logfiles.php in Netsweeper 4.0.3 and 4.0.4 allows remote attackers to injectnetsweeper · netsweeper · CWE-79 | Medium6.1 | — | 4.7% | Feb 19, 2020 |
25Monitor | CVE-2014-9608Proof of concept | Cross-site scripting (XSS) vulnerability in webadmin/policy/group_table_ajax.php/ in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.xnetsweeper · netsweeper · CWE-79 | Medium6.1 | — | 4.7% | Feb 19, 2020 |
25Monitor | CVE-2014-9606Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allow remote attnetsweeper · netsweeper · CWE-79 | Medium6.1 | — | 4.1% | Feb 19, 2020 |
25Monitor | CVE-2014-9615Proof of concept | Cross-site scripting (XSS) vulnerability in Netsweeper 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the url paranetsweeper · netsweeper · CWE-79 | Medium6.1 | — | 4.1% | Feb 19, 2020 |
22Monitor | CVE-2014-9610Proof of concept | Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and remove IP addressenetsweeper · netsweeper · CWE-264 | Medium5.3 | — | 3.7% | Sep 19, 2017 |
17Monitor | CVE-2012-2446No exploit | Cross-site scripting (XSS) vulnerability in tools/local_lookup.php in the WebAdmin Portal in Netsweeper allows remote attackers to inject arnetsweeper · netsweeper · CWE-79 | Medium4.3 | — | 1.1% | Jul 9, 2012 |
- CVE-2020-1316767This week
Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) la
CriticalCVSS 9.8WeaponizedEPSS 95%netsweeper · netsweeperMay 19, 2020
- CVE-2014-961861This week
The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass aut
CriticalCVSS 9.8Proof of conceptEPSS 73%netsweeper · netsweeperSep 19, 2017
- CVE-2014-961460This week
The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attac
CriticalCVSS 9.8Proof of conceptEPSS 69%netsweeper · netsweeperFeb 19, 2020
- CVE-2014-961143Plan
Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to webadmi
CriticalCVSS 9.8Proof of conceptEPSS 13%netsweeper · netsweeperSep 19, 2017
- CVE-2012-385941Plan
Unspecified vulnerability in the WebAdmin Portal in Netsweeper has unknown impact and attack vectors, a different vulnerability than CVE-201
CriticalCVSS 10.0Proof of conceptEPSS 3%netsweeper · netsweeperJul 9, 2012
- CVE-2014-961240Plan
SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allo
CriticalCVSS 9.8Proof of conceptEPSS 5%netsweeper · netsweeperFeb 19, 2020
- CVE-2014-961340Plan
Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL commands via the (1) l
CriticalCVSS 9.8Proof of conceptEPSS 4%netsweeper · netsweeperFeb 19, 2020
- CVE-2014-960538Monitor
WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and crea
CriticalCVSS 9.4Proof of conceptEPSS 4%netsweeper · netsweeperSep 4, 2015
- CVE-2014-961631Monitor
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to obtain sensitive information by making a req
HighCVSS 7.5No exploitEPSS 2%netsweeper · netsweeperSep 19, 2017
- CVE-2014-961930Monitor
Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and
HighCVSS 7.2Proof of conceptEPSS 7%netsweeper · netsweeperSep 19, 2017
- CVE-2012-244727Monitor
Cross-site request forgery (CSRF) vulnerability in accountmgr/adminupdate.php in the WebAdmin Portal in Netsweeper allows remote attackers t
MediumCVSS 6.8No exploitEPSS 1%netsweeper · netsweeperJul 9, 2012
- CVE-2014-961726Monitor
Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbi
MediumCVSS 6.1Proof of conceptEPSS 8%netsweeper · netsweeperFeb 19, 2020
- CVE-2014-960925Monitor
Directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before
MediumCVSS 5.3Proof of conceptEPSS 13%netsweeper · netsweeperFeb 19, 2020
- CVE-2014-960725Monitor
Cross-site scripting (XSS) vulnerability in remotereporter/load_logfiles.php in Netsweeper 4.0.3 and 4.0.4 allows remote attackers to inject
MediumCVSS 6.1Proof of conceptEPSS 5%netsweeper · netsweeperFeb 19, 2020
- CVE-2014-960825Monitor
Cross-site scripting (XSS) vulnerability in webadmin/policy/group_table_ajax.php/ in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x
MediumCVSS 6.1Proof of conceptEPSS 5%netsweeper · netsweeperFeb 19, 2020
- CVE-2014-960625Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allow remote att
MediumCVSS 6.1Proof of conceptEPSS 4%netsweeper · netsweeperFeb 19, 2020
- CVE-2014-961525Monitor
Cross-site scripting (XSS) vulnerability in Netsweeper 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the url para
MediumCVSS 6.1Proof of conceptEPSS 4%netsweeper · netsweeperFeb 19, 2020
- CVE-2014-961022Monitor
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and remove IP addresse
MediumCVSS 5.3Proof of conceptEPSS 4%netsweeper · netsweeperSep 19, 2017
- CVE-2012-244617Monitor
Cross-site scripting (XSS) vulnerability in tools/local_lookup.php in the WebAdmin Portal in Netsweeper allows remote attackers to inject ar
MediumCVSS 4.3No exploitEPSS 1%netsweeper · netsweeperJul 9, 2012