CVE-2014-9612

CRITICAL

Netsweeper <4.1.2 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to execute arbitrary SQL commands via the server parameter.

Exploits (1)

exploitdb WRITEUP
by Anastasios Monachos · textwebappsphp
https://www.exploit-db.com/exploits/37927

Scores

CVSS v3 9.8
EPSS 0.0624
EPSS Percentile 90.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
netsweeper/netsweeper < 3.1.10
Published Feb 19, 2020
Tracked Since Feb 18, 2026