4
CVSSv2

CVE-2012-1258

Published: 09/01/2020 Updated: 22/01/2020
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer prior to 9.0.1.19899 does not validate user permissions, which allow remote malicious users to add user accounts with administrator privileges via the newuser, pwd, and selectedUserGroup parameters.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

plixer scrutinizer netflow \\& sflow analyzer

Exploits

Trustwave SpiderLabs Security Advisory TWSL2012-008: Multiple Vulnerabilities in Scrutinizer NetFlow & sFlow Analyzer wwwtrustwavecom/spiderlabs/advisories/TWSL2012-008txt Published: 04/11/12 Version: 10 Vendor: Plixer International (wwwplixercom) Product: Scrutinizer NetFlow and sFlow Analyzer Version affected: 862 ( ...
Scrutinizer NetFlow and sFlow Analyzer version 862 suffers from authentication bypass, cross site scripting, and remote SQL injection vulnerabilities ...