Vulnerabilities (CVE)

Filtered by vendor Netsweeper Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-9605 1 Netsweeper 1 Netsweeper 2019-02-01 9.4 HIGH N/A
WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a system backup tarball, restart the server, or stop the filters on the server via a ' (single quote) character in the login and password parameters to webupgrade/webupgrade.php. NOTE: this was originally reported as an SQL injection vulnerability, but this may be inaccurate.
CVE-2012-3859 1 Netsweeper 1 Netsweeper 2012-07-10 10.0 HIGH N/A
Unspecified vulnerability in the WebAdmin Portal in Netsweeper has unknown impact and attack vectors, a different vulnerability than CVE-2012-2446 and CVE-2012-2447.
CVE-2012-2447 1 Netsweeper 1 Netsweeper 2012-07-10 6.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in accountmgr/adminupdate.php in the WebAdmin Portal in Netsweeper allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts via an add action.
CVE-2012-2446 1 Netsweeper 1 Netsweeper 2012-07-10 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in tools/local_lookup.php in the WebAdmin Portal in Netsweeper allows remote attackers to inject arbitrary web script or HTML via the group parameter in a lookup action.