7.2
CVSSv3

CVE-2014-9619

Published: 19/09/2017 Updated: 27/09/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper prior to 3.1.10, 4.0.x prior to 4.0.9, and 4.1.x prior to 4.1.2 allows remote authenticated users with admin privileges on the Cloud Manager web console to execute arbitrary PHP code by uploading a file with a double extension, then accessing it via a direct request to the file in webadmin/deny/images/, as demonstrated by secuid0.php.gif.

Vulnerable Product Search on Vulmon Subscribe to Product

netsweeper netsweeper 4.0.7

netsweeper netsweeper 4.0.5

netsweeper netsweeper 4.0.3

netsweeper netsweeper 4.0.2

netsweeper netsweeper 4.0.1

netsweeper netsweeper 4.0.0

netsweeper netsweeper 4.0.8

netsweeper netsweeper 4.0.6

netsweeper netsweeper 4.0.4

netsweeper netsweeper

netsweeper netsweeper 4.1.1

netsweeper netsweeper 4.1.0

Exploits

+--------------------------------------------------------+ + Netsweeper 408 - Arbitrary File Upload and Execution + +--------------------------------------------------------+ Affected Product: Netsweeper Vendor Homepage : wwwnetsweepercom Version : 408 (and probably other versions) Discovered by : Anastasios Monachos (secuid0) - [anastasio ...