Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Netsweeper CRITICAL 9.8
CVE-2020-13167EPSS 95%

Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a …

Fix: after 6.4.3
Fix from $2,300 2020-05-19
Netsweeper MEDIUM 6.1
CVE-2014-9617EPSS 8%

Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbitrary web…

Fix: 4.0.5+
Fix from $1,600 2020-02-19
Netsweeper CRITICAL 9.8
CVE-2014-9612

SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote…

Fix: 3.1.10 / 4.0.9+
Fix from $2,300 2020-02-19
Netsweeper CRITICAL 9.8
CVE-2014-9613

Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL commands via the (1) login para…

Fix: 2.6.29.10+
Fix from $2,300 2020-02-19
Netsweeper CRITICAL 9.8
CVE-2014-9614EPSS 69%

The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attackers to o…

Fix: 4.0.5+
Fix from $2,300 2020-02-19
Netsweeper MEDIUM 6.1
CVE-2014-9606

Multiple cross-site scripting (XSS) vulnerabilities in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allow remote attackers to…

Fix: 3.1.10 / 4.0.9+
Fix from $1,600 2020-02-19
Netsweeper MEDIUM 6.1
CVE-2014-9607

Cross-site scripting (XSS) vulnerability in remotereporter/load_logfiles.php in Netsweeper 4.0.3 and 4.0.4 allows remote attackers to inject arbitrar…

No fix yet
Fix from $1,600 2020-02-19
Netsweeper MEDIUM 6.1
CVE-2014-9608

Cross-site scripting (XSS) vulnerability in webadmin/policy/group_table_ajax.php/ in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4…

Fix: 3.1.10 / 4.0.9+
Fix from $1,600 2020-02-19
Netsweeper MEDIUM 6.1
CVE-2014-9615

Cross-site scripting (XSS) vulnerability in Netsweeper 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the url parameter to …

No fix yet
Fix from $1,600 2020-02-19
Netsweeper MEDIUM 5.3
CVE-2014-9609EPSS 13%

Directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 al…

Fix: 3.1.10 / 4.0.9+
Fix from $1,600 2020-02-19
Netsweeper CRITICAL 9.8
CVE-2014-9611EPSS 13%

Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to webadmin/nslam/i…

Fix: after 4.0.4
Fix from $2,300 2017-09-19
Netsweeper CRITICAL 9.8
CVE-2014-9618EPSS 73%

The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authenticati…

Fix: after 3.1.9
Fix from $2,300 2017-09-19
Netsweeper HIGH 7.5
CVE-2014-9616

Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to obtain sensitive information by making a request that…

Fix: after 3.1.9
Fix from $1,950 2017-09-19
Netsweeper HIGH 7.2
CVE-2014-9619EPSS 7%

Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x bef…

Fix: after 3.1.9
Fix from $1,950 2017-09-19
Netsweeper MEDIUM 5.3
CVE-2014-9610

Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and remove IP addresses from th…

Fix: after 3.1.9
Fix from $1,600 2017-09-19
Netsweeper HIGH 9.4
CVE-2014-9605

WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a syst…

Fix: 3.1.10 / 4.0.9+
Fix from $1,950 2015-09-04
Netsweeper HIGH 10.0
CVE-2012-3859

Unspecified vulnerability in the WebAdmin Portal in Netsweeper has unknown impact and attack vectors, a different vulnerability than CVE-2012-2446 an…

No fix yet
Fix from $1,950 2012-07-09
Netsweeper MEDIUM 6.8
CVE-2012-2447

Cross-site request forgery (CSRF) vulnerability in accountmgr/adminupdate.php in the WebAdmin Portal in Netsweeper allows remote attackers to hijack …

No fix yet
Fix from $1,600 2012-07-09