Back to search
CVE-2014-5464
Published: Sep 8, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20140903 Re: ntopng 1.2.0 XSS injection using monitored network traffic
mailing-list
x_refsource_BUGTRAQ
http://www.ntop.org/ndpi/released-ndpi-1-5-1-and-ntopng-1-2-1/
x_refsource_CONFIRM
20140909 Re: ntopng 1.2.0 XSS injection using monitored network traffic
mailing-list
x_refsource_FULLDISC
ntopng-httpheader-xss(95461)
vdb-entry
x_refsource_XF
60096
third-party-advisory
x_refsource_SECUNIA
110437
vdb-entry
x_refsource_OSVDB
20140825 ntopng 1.2.0 XSS injection using monitored network traffic
mailing-list
x_refsource_FULLDISC
20140903 Re: ntopng 1.2.0 XSS injection using monitored network traffic
mailing-list
x_refsource_FULLDISC
34419
exploit
x_refsource_EXPLOIT-DB
69385
vdb-entry
x_refsource_BID
20140825 ntopng 1.2.0 XSS injection using monitored network traffic
mailing-list
x_refsource_BUGTRAQ
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now