peter bassill · operator
$ cve CVE-2014-9619 JSON

CVE-2014-9619 EXPLOIT

7.2
HIGH · CVSS 3.0 · EPSS 7.4% (pctl 94)

Patch early

A public exploit exists.

Description

Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote authenticated users with admin privileges on the Cloud Manager web console to execute arbitrary PHP code by uploading a file with a double extension, then accessing it via a direct request to the file in webadmin/deny/images/, as demonstrated by secuid0.php.gif.

Scoring

CVSS7.2 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS7.35% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploityes
Published2017-09-19
Last modified2026-06-17

Affected (1)

VendorProduct
netsweepernetsweeper

Public exploits

SourceTitleDate
exploit-dbNetsweeper 4.0.8 - Arbitrary File Upload / Execution2015-08-21

References

→ the Explorer  ·  watch your stack  ·  NVD