MidnightBSD

Advisories for netsupport

CVE-2004-1861 MEDIUM

Invision NetSupport School Pro uses a weak encryption algorithm to encrypt passwords, which allows local users to obtain passwords.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
netsupport netsupport_school 7.0
netsupport netsupport_school 7.0_1
netsupport netsupport_school 7.5
CVE-2004-2737 HIGH

SQL injection vulnerability in problist.asp in NetSupport DNA HelpDesk 1.01 allows remote attackers to execute arbitrary SQL commands via the where parameter.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
netsupport dna_helpdesk 1.01
CVE-2007-5057 HIGH

NetSupport Manager Client before 10.20.0004 allows remote attackers to bypass the (1) basic and (2) authentication schemes by spoofing the NetSupport Manager.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,

Products Affected

Vendor Product Version
netsupport netsupport_manager_client 9.10
netsupport netsupport_manager_client 5.02_f1
netsupport netsupport_manager_client 8.50
netsupport netsupport_manager_client 8.60
netsupport netsupport_manager_client 5.02
netsupport netsupport_manager_client 8.10
netsupport netsupport_manager_client 7.10
netsupport netsupport_manager_client 9.60
netsupport netsupport_manager_client 10.00
netsupport netsupport_manager_client 5.05
netsupport netsupport_manager_client 10.20
netsupport netsupport_manager_client 5.30
netsupport netsupport_manager_client 9.50
netsupport netsupport_manager_client 5.00
netsupport netsupport_manager_client 5.01
netsupport netsupport_manager_client 7.01
netsupport netsupport_manager_client 5.03
netsupport netsupport_manager_client 6.11
netsupport netsupport_manager_client 9.00
netsupport netsupport_manager_client 5.31
netsupport netsupport_manager_client 6.10
netsupport netsupport_manager_client 6.00
netsupport netsupport_manager_client 8.00
CVE-2007-5252 HIGH

Buffer overflow in NetSupport Manager (NSM) Client 10.00 and 10.20, and NetSupport School Student (NSS) 9.00, allows remote NSM servers to cause a denial of service or possibly execute arbitrary code via crafted data in the configuration exchange phase of an initial connection setup. NOTE: a vendor statement, which is too vague to be sure that it is for this particular issue, says that only a denial of service is possible.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
netsupport netsupport_school_student 9.00
netsupport netsupport_manager_client 10.00
netsupport netsupport_manager_client 10.20
CVE-2011-0404 HIGH

Stack-based buffer overflow in NetSupport Manager Agent for Linux 11.00, for Solaris 9.50, and for Mac OS X 11.00 allows remote attackers to execute arbitrary code via a long control hostname to TCP port 5405, probably a different vulnerability than CVE-2007-5252.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
netsupport netsupport_manager_agent 11.00
netsupport netsupport_manager_agent 9.50