4.3
CVSSv2

CVE-2014-4329

Published: 19/06/2014 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in lua/host_details.lua in ntopng 1.1 allows remote malicious users to inject arbitrary web script or HTML via the host parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

ntop ntopng 1.1

Vendor Advisories

Debian Bug report logs - #760990 ntopng: Several vulnerabilities fixed upstream in 121 Package: src:ntopng; Maintainer for src:ntopng is Ludovico Cavedon <cavedon@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 9 Sep 2014 18:09:01 UTC Severity: grave Tags: fixed-upstream, security, up ...

Exploits

Ntop-NG version 11 suffers from a reflective cross site scripting vulnerability ...