Known Vulnerabilities for products from Netsweeper
Listed below are 19 of the newest known vulnerabilities associated with the vendor "Netsweeper".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-13167 json | Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Refe... | 9.8 - CRITICAL | 2020-05-19 | 2021-07-21 |
| CVE-2014-9619 json | Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x bef... | 7.2 - HIGH | 2017-09-19 | 2017-09-27 |
| CVE-2014-9618 json | The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attacker... | 9.8 - CRITICAL | 2017-09-19 | 2017-09-29 |
| CVE-2014-9617 json | Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirec... | 6.1 - MEDIUM | 2020-02-19 | 2020-02-20 |
| CVE-2014-9616 json | Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to obtain sensitive information ... | 7.5 - HIGH | 2017-09-19 | 2017-09-27 |
| CVE-2014-9615 json | Cross-site scripting (XSS) vulnerability in Netsweeper 4.0.4 allows remote attackers to inject arbitrary web script or HTML v... | 6.1 - MEDIUM | 2020-02-19 | 2020-02-20 |
| CVE-2014-9614 json | The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier f... | 9.8 - CRITICAL | 2020-02-19 | 2020-02-20 |
| CVE-2014-9613 json | Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL command... | 9.8 - CRITICAL | 2020-02-19 | 2020-02-20 |
| CVE-2014-9612 json | SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x be... | 9.8 - CRITICAL | 2020-02-19 | 2020-02-20 |
| CVE-2014-9611 json | Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a req... | 9.8 - CRITICAL | 2017-09-19 | 2017-09-27 |
| CVE-2014-9610 json | Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and rem... | 5.3 - MEDIUM | 2017-09-19 | 2017-09-27 |
| CVE-2014-9609 json | Directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, a... | 5.3 - MEDIUM | 2020-02-19 | 2020-02-20 |
| CVE-2014-9608 json | Cross-site scripting (XSS) vulnerability in webadmin/policy/group_table_ajax.php/ in Netsweeper before 3.1.10, 4.0.x before 4... | 6.1 - MEDIUM | 2020-02-19 | 2020-02-20 |
| CVE-2014-9607 json | Cross-site scripting (XSS) vulnerability in remotereporter/load_logfiles.php in Netsweeper 4.0.3 and 4.0.4 allows remote atta... | 6.1 - MEDIUM | 2020-02-19 | 2020-02-20 |
| CVE-2014-9606 json | Multiple cross-site scripting (XSS) vulnerabilities in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 a... | 6.1 - MEDIUM | 2020-02-19 | 2020-02-20 |
| CVE-2014-9605 json | WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authenti... | Not Provided | 2015-09-04 | 2026-05-06 |
| CVE-2012-3859 json | Unspecified vulnerability in the WebAdmin Portal in Netsweeper has unknown impact and attack vectors, a different vulnerabili... | Not Provided | 2012-07-09 | 2026-04-29 |
| CVE-2012-2447 json | Cross-site request forgery (CSRF) vulnerability in accountmgr/adminupdate.php in the WebAdmin Portal in Netsweeper allows rem... | Not Provided | 2012-07-09 | 2026-04-29 |
| CVE-2012-2446 json | Cross-site scripting (XSS) vulnerability in tools/local_lookup.php in the WebAdmin Portal in Netsweeper allows remote attacke... | Not Provided | 2012-07-09 | 2026-04-29 |
Known software with vulnerabilities from Netsweeper
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Netsweeper | Netsweeper | 2.6.29.1 |