7.5
CVSSv2

CVE-2002-0412

Published: 12/08/2002 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Format string vulnerability in TraceEvent function for ntop prior to 2.1 allows remote malicious users to execute arbitrary code by causing format strings to be injected into calls to the syslog function, via (1) an HTTP GET request, (2) a user name in HTTP authentication, or (3) a password in HTTP authentication.

Vulnerable Product Search on Vulmon Subscribe to Product

luca deri ntop 2.0