Vulnerability Note VU#763795
Netsweeper Internet Filter WebAdmin Portal multiple vulnerabilities
Overview
Netsweeper Internet Filter WebAdmin Portal contains XSS, CSRF and SQLi vulnerabilities.
Description
Netsweeper Internet Filter's WebAdmin Portal contains the following XSS, CSRF and SQLi vulnerabilities. CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2012-2446: |
Impact
An attacker with access to the Netsweeper Internet Filter WebAdmin Portal web interface can conduct a cross-site scripting, cross-site request forgery, or sql injection attack, which could be used to result in information leakage, privilege escalation, and/or denial of service. |
Solution
Update |
Restrict access |
Vendor Information (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| netsweeper | Affected | 04 Jun 2012 | 28 Jun 2012 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | 6.3 | AV:N/AC:M/Au:S/C:C/I:N/A:N |
| Temporal | 4.8 | E:POC/RL:W/RC:UC |
| Environmental | 1.3 | CDP:L/TD:L/CR:ND/IR:ND/AR:ND |
References
- http://www.netsweeper.com/
- http://cwe.mitre.org/data/definitions/79.html
- http://cwe.mitre.org/data/definitions/352.html
- http://cwe.mitre.org/data/definitions/89.html
- http://infosec42.blogspot.com/2012/07/cve-2012-2446-cve-2012-2447-cve-2012.html
Credit
Thanks to Jacob Holcomb of Leland Public Schools for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
- CVE IDs: CVE-2012-2446 CVE-2012-2447 CVE-2012-3859
- Date Public: 09 Jul 2012
- Date First Published: 09 Jul 2012
- Date Last Updated: 20 Aug 2012
- Document Revision: 24
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.