Required CVE Record Information
Description
The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and subsequently create arbitrary profiles via a showdeny action to the default URL.
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 2 Total
- http://packetstormsecurity.com/files/133034/Netsweeper-Bypass-XSS-Redirection-SQL-Injection-Execution.html x_transferred
- exploit-db.com: 37933 exploitx_transferred