CVE-2014-9619

HIGH

Netsweeper <4.1.2 - RCE

Title source: llm
STIX 2.1

Description

Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote authenticated users with admin privileges on the Cloud Manager web console to execute arbitrary PHP code by uploading a file with a double extension, then accessing it via a direct request to the file in webadmin/deny/images/, as demonstrated by secuid0.php.gif.

Exploits (1)

exploitdb WRITEUP
by Anastasios Monachos · textwebappsphp
https://www.exploit-db.com/exploits/37932

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/37932/

Scores

CVSS v3 7.2
EPSS 0.0646
EPSS Percentile 91.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (12)
netsweeper/netsweeper 4.0.0
netsweeper/netsweeper 4.0.1
netsweeper/netsweeper 4.0.2
netsweeper/netsweeper 4.0.3
netsweeper/netsweeper 4.0.4
netsweeper/netsweeper 4.0.5
netsweeper/netsweeper 4.0.6
netsweeper/netsweeper 4.0.7
netsweeper/netsweeper 4.0.8
netsweeper/netsweeper 4.1.0
... and 2 more
Published Sep 19, 2017
Tracked Since Feb 18, 2026