Record summary

CVE-2014-9617 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMNetsweeper 3.0.6 - Open RedirectionCVSS 6.1

An open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.

Impact

An attacker can exploit this vulnerability to redirect users to malicious websites, leading to potential phishing attacks or the download of malware.

Remediation

Apply the latest security patches or updates provided by the vendor to fix the open redirection vulnerability.

WeaknessesCWE-601
Authorsdaffainfo
Template tagscve2014cvenetsweeperredirectpacketstormxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:netsweeper:netsweeper:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2