CVE-2015-8368

ntopng <2.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to admin/password_reset.lua.

Exploits (1)

exploitdb WRITEUP
by Dolev Farhi · textwebappsmultiple
https://www.exploit-db.com/exploits/38836

References (3)

Core 3
Core References
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Dec/10
Exploit exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/38836/

Scores

EPSS 0.0299
EPSS Percentile 86.6%

Details

CWE
CWE-254
Status published
Products (1)
ntop/ntopng < 2.0.151021
Published Dec 17, 2015
Tracked Since Feb 18, 2026