Записи netsweeper
19 опубликованных записей вендора netsweeper.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 5,3 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-287 Improper Authentication3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
19 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
67На этой неделе | CVE-2020-13167Готовый эксплойт | Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) lanetsweeper · netsweeper · CWE-78 | Критическая9,8 | — | 95,0 % | 19 мая 2020 г. |
61На этой неделе | CVE-2014-9618Proof of concept | The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass autnetsweeper · netsweeper · CWE-287 | Критическая9,8 | — | 72,7 % | 19 сент. 2017 г. |
60На этой неделе | CVE-2014-9614Proof of concept | The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attacnetsweeper · netsweeper · CWE-798 | Критическая9,8 | — | 68,7 % | 19 февр. 2020 г. |
43В плане | CVE-2014-9611Proof of concept | Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to webadminetsweeper · netsweeper · CWE-287 | Критическая9,8 | — | 12,7 % | 19 сент. 2017 г. |
41В плане | CVE-2012-3859Proof of concept | Unspecified vulnerability in the WebAdmin Portal in Netsweeper has unknown impact and attack vectors, a different vulnerability than CVE-201netsweeper · netsweeper | Критическая10,0 | — | 2,9 % | 9 июл. 2012 г. |
40В плане | CVE-2014-9612Proof of concept | SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allonetsweeper · netsweeper · CWE-89 | Критическая9,8 | — | 4,9 % | 19 февр. 2020 г. |
40В плане | CVE-2014-9613Proof of concept | Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL commands via the (1) lnetsweeper · netsweeper · CWE-89 | Критическая9,8 | — | 4,1 % | 19 февр. 2020 г. |
38Наблюдать | CVE-2014-9605Proof of concept | WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and creanetsweeper · netsweeper · CWE-287 | Критическая9,4 | — | 3,9 % | 4 сент. 2015 г. |
31Наблюдать | CVE-2014-9616Эксплойта нет | Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to obtain sensitive information by making a reqnetsweeper · netsweeper · CWE-200 | Высокая7,5 | — | 2,4 % | 19 сент. 2017 г. |
30Наблюдать | CVE-2014-9619Proof of concept | Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and netsweeper · netsweeper · CWE-434 | Высокая7,2 | — | 7,4 % | 19 сент. 2017 г. |
27Наблюдать | CVE-2012-2447Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in accountmgr/adminupdate.php in the WebAdmin Portal in Netsweeper allows remote attackers tnetsweeper · netsweeper · CWE-352 | Средняя6,8 | — | 0,7 % | 9 июл. 2012 г. |
26Наблюдать | CVE-2014-9617Proof of concept | Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbinetsweeper · netsweeper · CWE-601 | Средняя6,1 | — | 8,0 % | 19 февр. 2020 г. |
25Наблюдать | CVE-2014-9609Proof of concept | Directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x beforenetsweeper · netsweeper · CWE-22 | Средняя5,3 | — | 12,6 % | 19 февр. 2020 г. |
25Наблюдать | CVE-2014-9607Proof of concept | Cross-site scripting (XSS) vulnerability in remotereporter/load_logfiles.php in Netsweeper 4.0.3 and 4.0.4 allows remote attackers to injectnetsweeper · netsweeper · CWE-79 | Средняя6,1 | — | 4,7 % | 19 февр. 2020 г. |
25Наблюдать | CVE-2014-9608Proof of concept | Cross-site scripting (XSS) vulnerability in webadmin/policy/group_table_ajax.php/ in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.xnetsweeper · netsweeper · CWE-79 | Средняя6,1 | — | 4,7 % | 19 февр. 2020 г. |
25Наблюдать | CVE-2014-9606Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allow remote attnetsweeper · netsweeper · CWE-79 | Средняя6,1 | — | 4,1 % | 19 февр. 2020 г. |
25Наблюдать | CVE-2014-9615Proof of concept | Cross-site scripting (XSS) vulnerability in Netsweeper 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the url paranetsweeper · netsweeper · CWE-79 | Средняя6,1 | — | 4,1 % | 19 февр. 2020 г. |
22Наблюдать | CVE-2014-9610Proof of concept | Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and remove IP addressenetsweeper · netsweeper · CWE-264 | Средняя5,3 | — | 3,7 % | 19 сент. 2017 г. |
17Наблюдать | CVE-2012-2446Эксплойта нет | Cross-site scripting (XSS) vulnerability in tools/local_lookup.php in the WebAdmin Portal in Netsweeper allows remote attackers to inject arnetsweeper · netsweeper · CWE-79 | Средняя4,3 | — | 1,1 % | 9 июл. 2012 г. |
- CVE-2020-1316767На этой неделе
Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) la
КритическаяCVSS 9,8Готовый эксплойтEPSS 95 %netsweeper · netsweeper19 мая 2020 г.
- CVE-2014-961861На этой неделе
The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass aut
КритическаяCVSS 9,8Proof of conceptEPSS 73 %netsweeper · netsweeper19 сент. 2017 г.
- CVE-2014-961460На этой неделе
The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attac
КритическаяCVSS 9,8Proof of conceptEPSS 69 %netsweeper · netsweeper19 февр. 2020 г.
- CVE-2014-961143В плане
Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to webadmi
КритическаяCVSS 9,8Proof of conceptEPSS 13 %netsweeper · netsweeper19 сент. 2017 г.
- CVE-2012-385941В плане
Unspecified vulnerability in the WebAdmin Portal in Netsweeper has unknown impact and attack vectors, a different vulnerability than CVE-201
КритическаяCVSS 10,0Proof of conceptEPSS 3 %netsweeper · netsweeper9 июл. 2012 г.
- CVE-2014-961240В плане
SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allo
КритическаяCVSS 9,8Proof of conceptEPSS 5 %netsweeper · netsweeper19 февр. 2020 г.
- CVE-2014-961340В плане
Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL commands via the (1) l
КритическаяCVSS 9,8Proof of conceptEPSS 4 %netsweeper · netsweeper19 февр. 2020 г.
- CVE-2014-960538Наблюдать
WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and crea
КритическаяCVSS 9,4Proof of conceptEPSS 4 %netsweeper · netsweeper4 сент. 2015 г.
- CVE-2014-961631Наблюдать
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to obtain sensitive information by making a req
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %netsweeper · netsweeper19 сент. 2017 г.
- CVE-2014-961930Наблюдать
Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and
ВысокаяCVSS 7,2Proof of conceptEPSS 7 %netsweeper · netsweeper19 сент. 2017 г.
- CVE-2012-244727Наблюдать
Cross-site request forgery (CSRF) vulnerability in accountmgr/adminupdate.php in the WebAdmin Portal in Netsweeper allows remote attackers t
СредняяCVSS 6,8Эксплойта нетEPSS 1 %netsweeper · netsweeper9 июл. 2012 г.
- CVE-2014-961726Наблюдать
Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbi
СредняяCVSS 6,1Proof of conceptEPSS 8 %netsweeper · netsweeper19 февр. 2020 г.
- CVE-2014-960925Наблюдать
Directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before
СредняяCVSS 5,3Proof of conceptEPSS 13 %netsweeper · netsweeper19 февр. 2020 г.
- CVE-2014-960725Наблюдать
Cross-site scripting (XSS) vulnerability in remotereporter/load_logfiles.php in Netsweeper 4.0.3 and 4.0.4 allows remote attackers to inject
СредняяCVSS 6,1Proof of conceptEPSS 5 %netsweeper · netsweeper19 февр. 2020 г.
- CVE-2014-960825Наблюдать
Cross-site scripting (XSS) vulnerability in webadmin/policy/group_table_ajax.php/ in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x
СредняяCVSS 6,1Proof of conceptEPSS 5 %netsweeper · netsweeper19 февр. 2020 г.
- CVE-2014-960625Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allow remote att
СредняяCVSS 6,1Proof of conceptEPSS 4 %netsweeper · netsweeper19 февр. 2020 г.
- CVE-2014-961525Наблюдать
Cross-site scripting (XSS) vulnerability in Netsweeper 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the url para
СредняяCVSS 6,1Proof of conceptEPSS 4 %netsweeper · netsweeper19 февр. 2020 г.
- CVE-2014-961022Наблюдать
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and remove IP addresse
СредняяCVSS 5,3Proof of conceptEPSS 4 %netsweeper · netsweeper19 сент. 2017 г.
- CVE-2012-244617Наблюдать
Cross-site scripting (XSS) vulnerability in tools/local_lookup.php in the WebAdmin Portal in Netsweeper allows remote attackers to inject ar
СредняяCVSS 4,3Эксплойта нетEPSS 1 %netsweeper · netsweeper9 июл. 2012 г.