Vulnerabilities > CVE-2015-8368 - 7PK - Security Features vulnerability in Ntop Ntopng

047910
CVSS 6.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
ntop
CWE-254
exploit available

Summary

ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to admin/password_reset.lua.

Vulnerable Configurations

Part Description Count
Application
Ntop
4

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionntop-ng <= 2.0.151021 - Privilege Escalation. CVE-2015-8368. Webapps exploits for multiple platform
fileexploits/multiple/webapps/38836.txt
idEDB-ID:38836
last seen2016-02-04
modified2015-12-01
platformmultiple
port
published2015-12-01
reporterDolev Farhi
sourcehttps://www.exploit-db.com/download/38836/
titlentop-ng <= 2.0.151021 - Privilege Escalation
typewebapps

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/134593/ntopng20151021-escalate.txt
idPACKETSTORM:134593
last seen2016-12-05
published2015-12-02
reporterDolev Farhi
sourcehttps://packetstormsecurity.com/files/134593/ntop-ng-2.0.15102-Privilege-Escalation.html
titlentop-ng 2.0.15102 Privilege Escalation