CVE-2014-5464
CVE-2014-5464
Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.
Produtos afetados
n/a · n/aPoCs públicas encontradas — 3
cve_referencepacketstormsecurity.com/files/127995/ntopng-1.2.0-Cross-Site-Scripting.htmlnão verificadocve_referencewww.exploit-db.com/exploits/34419não verificadoexploitdbwww.exploit-db.com/exploits/34419não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://osvdb.org/show/osvdb/110437http://packetstormsecurity.com/files/127995/ntopng-1.2.0-Cross-Site-Scripting.htmlhttp://seclists.org/fulldisclosure/2014/Aug/65http://seclists.org/fulldisclosure/2014/Sep/22http://seclists.org/fulldisclosure/2014/Sep/28http://secunia.com/advisories/60096https://exchange.xforce.ibmcloud.com/vulnerabilities/95461http://www.exploit-db.com/exploits/34419http://www.ntop.org/ndpi/released-ndpi-1-5-1-and-ntopng-1-2-1/http://www.securityfocus.com/archive/1/533222/100/0/threadedhttp://www.securityfocus.com/archive/1/533332/100/0/threadedhttp://www.securityfocus.com/bid/69385