Home/Product/netsweeper
Product

netsweeper

19 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2020-13167
<= 6.4.3
Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer h
9.8CRITICAL
CVE-2014-9617
< 4.0.5
Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect use
6.1MEDIUM
CVE-2014-9615
all versions
Cross-site scripting (XSS) vulnerability in Netsweeper 4.0.4 allows remote attackers to inject arbitrary web script or HTML via th
6.1MEDIUM
CVE-2014-9614
< 4.0.5
The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for re
9.8CRITICAL
CVE-2014-9613
< 2.6.29.10
Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL commands via
9.8CRITICAL
CVE-2014-9612
< 3.1.10
SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before
9.8CRITICAL
CVE-2014-9609
< 3.1.10
Directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.
5.3MEDIUM
CVE-2014-9608
< 3.1.10
Cross-site scripting (XSS) vulnerability in webadmin/policy/group_table_ajax.php/ in Netsweeper before 3.1.10, 4.0.x before 4.0.9,
6.1MEDIUM
CVE-2014-9607
all versions
Cross-site scripting (XSS) vulnerability in remotereporter/load_logfiles.php in Netsweeper 4.0.3 and 4.0.4 allows remote attackers
6.1MEDIUM
CVE-2014-9606
< 3.1.10
Multiple cross-site scripting (XSS) vulnerabilities in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allow
6.1MEDIUM
CVE-2014-9619
<= 3.1.9
Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4
7.2HIGH
CVE-2014-9618
<= 3.1.9
The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to
9.8CRITICAL
CVE-2014-9616
<= 3.1.9
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to obtain sensitive information by ma
7.5HIGH
CVE-2014-9611
<= 4.0.4
Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request
9.8CRITICAL
CVE-2014-9610
<= 3.1.9
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and remove I
5.3MEDIUM
CVE-2014-9605
>= 3.1.0 and < 3.1.10
WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authenticatio
CVE-2012-3859
all versions
Unspecified vulnerability in the WebAdmin Portal in Netsweeper has unknown impact and attack vectors, a different vulnerability th
CVE-2012-2447
all versions
Cross-site request forgery (CSRF) vulnerability in accountmgr/adminupdate.php in the WebAdmin Portal in Netsweeper allows remote a
CVE-2012-2446
all versions
Cross-site scripting (XSS) vulnerability in tools/local_lookup.php in the WebAdmin Portal in Netsweeper allows remote attackers to
threatengine.sh