peter bassill · operator
$ cve CVE-2014-9605 JSON

CVE-2014-9605 EXPLOIT

9.4
HIGH · CVSS 2.0 · EPSS 3.9% (pctl 90)

Patch early

A public exploit exists.

Description

WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a system backup tarball, restart the server, or stop the filters on the server via a ' (single quote) character in the login and password parameters to webupgrade/webupgrade.php. NOTE: this was originally reported as an SQL injection vulnerability, but this may be inaccurate.

Scoring

CVSS9.4 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:N/A:C
EPSS3.94% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2015-09-04
Last modified2026-06-17

Affected (1)

VendorProduct
netsweepernetsweeper

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD