CVE-2014-9612
CRITICALNetsweeper < 3.1.10, 4.0.x < 4.0.9, 4.1.x < 4.1.2 - SQL Injection via Server Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-9612. PoCs published by Anastasios Monachos.
AI-analyzed exploit summary This is a writeup describing a SQL injection vulnerability in Netsweeper 4.0.4. The vulnerability exists in the 'server' parameter of the 'load_logfiles.php' page and can be exploited by unauthenticated users.
Description
SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to execute arbitrary SQL commands via the server parameter.
Exploits (1)
This is a writeup describing a SQL injection vulnerability in Netsweeper 4.0.4. The vulnerability exists in the 'server' parameter of the 'load_logfiles.php' page and can be exploited by unauthenticated users.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H