6.8
CVSSv2

CVE-2012-2447

Published: 09/07/2012 Updated: 10/07/2012
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in accountmgr/adminupdate.php in the WebAdmin Portal in Netsweeper allows remote malicious users to hijack the authentication of administrators for requests that create administrative accounts via an add action.

Vulnerable Product Search on Vulmon Subscribe to Product

netsweeper netsweeper

Exploits

Netsweeper WebAdmin Portal suffers from cross site request forgery, cross site scripting, and remote SQL injection vulnerabilities Note that most of this data released back in July of 2012 without the SQL injection information ...