ntopng (aka ntop) prior to 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to admin/password_reset.lua.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ntop ntopng |