Page 2 of 8 results (0.006 seconds)

CVSS: 6.0EPSS: 4%CPEs: 1EXPL: 3

ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to admin/password_reset.lua. ntopng (también conocido como ntop) en versiones anteriores a 2.2 permite a usuarios remotos autenticados cambiar el contexto de inicio de sesión y obtener privilegios a través del usuario cookie y el parámetro username en admin/password_reset.lua. ntop-ng versions 2.0.151021 and below suffer from a privilege escalation vulnerability. • https://www.exploit-db.com/exploits/38836 http://packetstormsecurity.com/files/134593/ntop-ng-2.0.15102-Privilege-Escalation.html http://seclists.org/fulldisclosure/2015/Dec/10 • CWE-254: 7PK - Security Features •

CVSS: 4.3EPSS: 1%CPEs: 2EXPL: 6

Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header. Vulnerabilidad de XSS en la libraría de la clasificación de trafico nDPI en ntopng (también conocido como ntop) anterior a 1.2.1 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de la cabecera HTTP Host. ntopng version 1.2.0 suffers from a cross site scripting vulnerability using monitored network traffic. • https://www.exploit-db.com/exploits/34419 http://osvdb.org/show/osvdb/110437 http://packetstormsecurity.com/files/127995/ntopng-1.2.0-Cross-Site-Scripting.html http://seclists.org/fulldisclosure/2014/Aug/65 http://seclists.org/fulldisclosure/2014/Sep/22 http://seclists.org/fulldisclosure/2014/Sep/28 http://secunia.com/advisories/60096 http://www.exploit-db.com/exploits/34419 http://www.ntop.org/ndpi/released-ndpi-1-5-1-and-ntopng-1-2-1 http://www.securityfocus.c • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 1

Cross-site scripting (XSS) vulnerability in lua/host_details.lua in ntopng 1.1 allows remote attackers to inject arbitrary web script or HTML via the host parameter. Vulnerabilidad de XSS en lua/host_details.lua en ntopng 1.1 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través del parámetro host. Ntop-NG version 1.1 suffers from a reflective cross site scripting vulnerability. • http://packetstormsecurity.com/files/127329/Ntop-NG-1.1-Cross-Site-Scripting.html http://www.ntop.org/ndpi/released-ndpi-1-5-1-and-ntopng-1-2-1 http://www.securityfocus.com/bid/66456 https://exchange.xforce.ibmcloud.com/vulnerabilities/92135 https://svn.ntop.org/bugzilla/show_bug.cgi?id=379 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •