CVE-2014-9613: Netsweeper

Critical severity, CVSS 9.8. EPSS: 4.1% chance of exploitation in the next 30 days.

Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL commands via the (1) login parameter to webadmin/auth/verification.php or (2) dpid parameter to webadmin/deny/index.php.

Affected products

  • Netsweeper Netsweeper: before 2.6.29.10 (fixed in 2.6.29.10)

Published 2020-02-19. Last modified 2026-06-17.