5
CVSSv2

CVE-2000-0705

Published: 20/10/2000 Updated: 10/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

ntop running in web mode allows remote malicious users to read arbitrary files via a .. (dot dot) attack.

Vulnerable Product Search on Vulmon Subscribe to Product

luca deri ntop 1.2a7_9

Exploits

source: wwwsecurityfocuscom/bid/1550/info ntop is a tool that shows the network usage, similar to what the popular top Unix command does Starting ntop in web mode (with the -w parameter) starts ntop with it's own built in HTTP server, to allow remote access to the functions it provides ntop does not properly authenticate requests and is ...