Record summary

CVE-2014-9609 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

Directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to list directory contents via a .. (dot dot) in the log parameter in a stats action.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMNetsweeper 4.0.8 - Directory TraversalCVSS 5.3

A directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to list directory contents via a .. (dot dot) in the log parameter in a stats action.

Impact

An attacker can read, modify, or delete arbitrary files on the server, potentially leading to unauthorized access, data leakage, or system compromise.

Remediation

Upgrade to a patched version of Netsweeper or apply the necessary security patches to fix the directory traversal vulnerability.

WeaknessesCWE-22
Authorsdaffainfo
Template tagscve2014cvenetsweeperlfipacketstormxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:netsweeper:netsweeper:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2