CVE-2014-9619
- EPSS 6.46%
- Veröffentlicht 19.09.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote authenticated users with admin privileges on the Cloud Manager web console to...
CVE-2014-9618
- EPSS 68.17%
- Veröffentlicht 19.09.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and subsequently create arbitrary profiles via a showdeny action to the default URL.
CVE-2014-9616
- EPSS 0.3%
- Veröffentlicht 19.09.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to obtain sensitive information by making a request that redirects to the deny page.
CVE-2014-9611
- EPSS 28.62%
- Veröffentlicht 19.09.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to webadmin/nslam/index.php.
CVE-2014-9610
- EPSS 13.36%
- Veröffentlicht 19.09.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and remove IP addresses from the quarantine via the ip parameter to webadmin/user/quarantine_disable.php.
CVE-2014-9605
- EPSS 8.69%
- Veröffentlicht 04.09.2015 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a system backup tarball, restart the server, or stop the filters on the server via a ' (single quote) chara...
- EPSS 12.75%
- Veröffentlicht 09.07.2012 18:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Unspecified vulnerability in the WebAdmin Portal in Netsweeper has unknown impact and attack vectors, a different vulnerability than CVE-2012-2446 and CVE-2012-2447.
CVE-2012-2446
- EPSS 0.3%
- Veröffentlicht 09.07.2012 18:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in tools/local_lookup.php in the WebAdmin Portal in Netsweeper allows remote attackers to inject arbitrary web script or HTML via the group parameter in a lookup action.
CVE-2012-2447
- EPSS 0.08%
- Veröffentlicht 09.07.2012 18:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site request forgery (CSRF) vulnerability in accountmgr/adminupdate.php in the WebAdmin Portal in Netsweeper allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts via an add acti...