.. / CVE-2014-9614

Exploit for Netsweeper 4.0.5 - Default Weak Account (CVE-2014-9614)

Description:

The Web Panel in Netsweeper before 4.0.5 has a default password of ‘branding’ for the branding account, which makes it easier for remote attackers to obtain access via a request to webadmin/.

Nuclei Template

View the template here CVE-2014-9614.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2014/CVE-2014-9614.yaml
Copy

References:

http://packetstormsecurity.com/files/133034/Netsweeper-Bypass-XSS-Redirection-SQL-Injection-Execution.html
https://github.com/ARPSyndicate/kenzer-templates
https://nvd.nist.gov/vuln/detail/CVE-2014-9614
https://packetstormsecurity.com/files/download/133034/netsweeper-issues.tgz