CVE-2015-8368

Source
https://cve.org/CVERecord?id=CVE-2015-8368
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2015-8368.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2015-8368
Downstream
Withdrawn
2024-12-09T18:56:24.136646Z
Published
2015-12-17T19:59:10Z
Modified
2024-09-18T02:14:54.899433Z
Summary
[none]
Details

ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to admin/password_reset.lua.

References

Affected packages

Debian:13 / ntopng

Package

Name
ntopng
Purl
pkg:deb/debian/ntopng?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2+dfsg1-1

Affected versions

1.*
1.1+dfsg2-1
1.1+dfsg2-2
1.2.0+dfsg1-1
1.2.1+dfsg1-1
1.2.1+dfsg1-1.1
1.2.1+dfsg1-2
2.*
2.0+dfsg1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2015-8368.json"