Netsweeper 漏洞列表
共找到 21 个与 Netsweeper 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2014-9606: Netsweeper 4.0.8 - Cross-Site Scripting POC
Multiple cross-site scripting vulnerabilities in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) server parameter to remotereporter/load_logfiles.php, (2) customctid parameter to webadmin/policy/category_table_ajax.php, (3) urllist parameter to webadmin/alert/alert.php, (4) QUERY_STRING to webadmin/ajaxfilemanager/ajax_get_file_listing.php, or (5) PATH_INFO to webadmin/policy/policy_table_ajax.php/. -
CVE-2014-9607: Netsweeper 4.0.4 - Cross-Site Scripting POC
A cross-site scripting vulnerability in remotereporter/load_logfiles.php in Netsweeper 4.0.3 and 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the url parameter. -
CVE-2014-9608: Netsweeper 4.0.3 - Cross-Site Scripting POC
A cross-site scripting vulnerability in webadmin/policy/group_table_ajax.php/ in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. -
CVE-2014-9609: Netsweeper 4.0.8 - Directory Traversal POC
A directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to list directory contents via a .. (dot dot) in the log parameter in a stats action. -
CVE-2014-9614: Netsweeper 4.0.5 - Default Weak Account POC
The Web Panel in Netsweeper before 4.0.5 has a default password of 'branding' for the branding account, which makes it easier for remote attackers to obtain access via a request to webadmin/. -
CVE-2014-9615: Netsweeper 4.0.4 - Cross-Site Scripting POC
A cross-site scripting vulnerability in Netsweeper 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the url parameter to webadmin/deny/index.php. -
CVE-2014-9617: Netsweeper 3.0.6 - Open Redirection POC
An open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter. -
CVE-2014-9618: Netsweeper - Authentication Bypass POC
The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and subsequently create arbitrary profiles via a showdeny action to the default URL. -
CVE-2020-13167: Netsweeper <=6.4.3 - Python Code Injection POC
Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a command line with client-supplied parameters, and allows injection of shell metacharacters. -
CVE-2014-9606: Netsweeper 4.0.8 - Cross-Site Scripting POC
Multiple cross-site scripting vulnerabilities in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) server parameter to remotereporter/load_logfiles.php, (2) customctid parameter to webadmin/policy/category_table_ajax.php, (3) urllist parameter to webadmin/alert/alert.php, (4) QUERY_STRING to webadmin/ajaxfilemanager/ajax_get_file_listing.php, or (5) PATH_INFO to webadmin/policy/policy_table_ajax.php/. -
CVE-2014-9607: Netsweeper 4.0.4 - Cross-Site Scripting POC
A cross-site scripting vulnerability in remotereporter/load_logfiles.php in Netsweeper 4.0.3 and 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the url parameter. -
CVE-2014-9608: Netsweeper 4.0.3 - Cross-Site Scripting POC
A cross-site scripting vulnerability in webadmin/policy/group_table_ajax.php/ in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. -
CVE-2014-9609: Netsweeper 4.0.8 - Directory Traversal POC
A directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to list directory contents via a .. (dot dot) in the log parameter in a stats action. -
CVE-2014-9614: Netsweeper 4.0.5 - Default Weak Account POC
The Web Panel in Netsweeper before 4.0.5 has a default password of 'branding' for the branding account, which makes it easier for remote attackers to obtain access via a request to webadmin/. -
CVE-2014-9615: Netsweeper 4.0.4 - Cross-Site Scripting POC
A cross-site scripting vulnerability in Netsweeper 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the url parameter to webadmin/deny/index.php. -
CVE-2014-9617: Netsweeper 3.0.6 - Open Redirection POC
An open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter. -
CVE-2014-9618: Netsweeper - Authentication Bypass POC
The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and subsequently create arbitrary profiles via a showdeny action to the default URL. -
CVE-2020-13167: Netsweeper <=6.4.3 - Python Code Injection POC
Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a command line with client-supplied parameters, and allows injection of shell metacharacters. -
netsweeper-open-redirect: Netsweeper 4.0.9 - Open Redirect POC
Netsweeper 4.0.9 contains an open redirect vulnerability. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations. -
netsweeper-rxss: Netsweeper 4.0.9 - Cross-Site Scripting POC
Netsweeper 4.0.9 contains a cross-site scripting vulnerability. An attacker can execute arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. -
Netsweeper 存在未授权远程代码执行漏洞(CVE-2020-13167) 无POC
Netsweeper是加拿大Netsweeper公司的一套Web内容过滤解决方案。Netsweeper6.4.3及之前版本中的/webadmin/tools/unixlogin.php脚本存在安全漏洞。攻击者可利用该漏洞执行代码。