CVE-2012-1258
Scrutinizer NetFlow & sFlow Analyzer - Multiple Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate user permissions, which allow remote attackers to add user accounts with administrator privileges via the newuser, pwd, and selectedUserGroup parameters.
El archivo cgi-bin/userprefs.cgi en Plixer International Scrutinizer NetFlow & sFlow Analyzer versiones anteriores a 9.0.1.19899, no comprueba los permisos de usuario, lo que permite a atacantes remotos agregar cuentas de usuario con privilegios de administrador por medio de los parĂ¡metros newuser, pwd y selectedUserGroup.
Scrutinizer NetFlow and sFlow Analyzer version 8.6.2 suffers from authentication bypass, cross site scripting, and remote SQL injection vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-02-22 CVE Reserved
- 2012-04-12 CVE Published
- 2012-04-19 First Exploit
- 2024-06-06 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-287: Improper Authentication
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/52989 | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/74824 | Vdb Entry | |
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/twsl2012-008-multiple-vulnerabilities-in-scrutinizer-netflow-sflow-analyzer | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/18750 | 2012-04-19 | |
http://packetstormsecurity.org/files/111791/Scrutinizer-8.6.2-Bypass-Cross-Site-Scripting-SQL-Injection.html | 2024-08-06 | |
http://www.exploit-db.com/exploits/18750 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Plixer Search vendor "Plixer" | Scrutinizer Netflow \& Sflow Analyzer Search vendor "Plixer" for product "Scrutinizer Netflow \& Sflow Analyzer" | < 9.0.1.19899 Search vendor "Plixer" for product "Scrutinizer Netflow \& Sflow Analyzer" and version " < 9.0.1.19899" | - |
Affected
|