HTTP: Ntop-ng Privilege Escalation

This signature detects attempts to exploit a known vulnerability against Ntop-ng. A successful attack can lead to elevation of privilege and arbitrary code execution.

Extended Description

ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to admin/password_reset.lua.

Affected Products

Ntop ntopng

References

CVE: CVE-2015-8368

Short Name
HTTP:CTS:NTOP-NG-PRIV-ESC
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
CVE-2015-8368 Escalation Ntop-ng Privilege
Release Date
02/04/2020
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Ntop

CVSS Score

6.0

Found a potential security threat?