CVE-2012-1258: Plixer Scrutinizer Netflow & Sflow Analyzer
Medium severity, CVSS 6.5. EPSS: 3.3% chance of exploitation in the next 30 days.
cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate user permissions, which allow remote attackers to add user accounts with administrator privileges via the newuser, pwd, and selectedUserGroup parameters.
Affected products
- Plixer Scrutinizer Netflow & Sflow Analyzer: before 9.0.1.19899 (fixed in 9.0.1.19899)
Published 2020-01-09. Last modified 2026-06-16.