vendor:
Netsweeper Internet Filter
by:
Jacob Holcomb/Gimppy042
9
CVSS
CRITICAL
CSRF, Reflective XSS, and SQL Injection
79 (Cross-Site Scripting), 352 (Cross-Site Request Forgery), 89 (SQL Injection)
CWE
Product Name: Netsweeper Internet Filter
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2012-2446 (XSS), CVE-2012-2447 (CSRF), CVE-2012-3859 (SQL Injection)
CPE: a:netsweeper:netsweeper_internet_filter
Platforms Tested: Unknown
2012
Netsweeper WebAdmin Portal CSRF, Reflective XSS, and SQL Injection
CSRF exploit allows for the creation of an administrator account by forging a HTTP POST request. Reflective XSS exploit exploits a reflective XSS vulnerability. SQL Injection exploit allows for SQL injection attacks.
Mitigation:
Implement input validation and sanitization to prevent CSRF, XSS, and SQL Injection attacks. Apply patches and updates provided by Netsweeper Inc.