PoC Index

CVE-2012-1258

MEDIUM 6.5EPSS 3.3%

cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate user permissions, which allow remote attackers to add user accounts with administrator privileges via the newuser, pwd, and selectedUserGroup parameters.

CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS v2.0
4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
EPSS
3.33% chance of exploitation in the next 30 days, 88th percentile
Published
2020-01-09
Updated
2024-08-06

Proof-of-concept exploits (2)

ExploitDB entries (1)

References

Related