CVE-2014-4165: XSS
Published Jun 16, 2014
·Updated
Cross-site scripting (XSS) vulnerability in ntop allows remote attackers to inject arbitrary web script or HTML via the title parameter in a list action to plugins/rrdPlugin.
Affected Software
3 affected components
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
ntop ntop
Event History
Jun 16, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-4165?
CVE-2014-4165 has a medium severity rating due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2014-4165?
To fix CVE-2014-4165, update to the latest version of ntop that addresses this XSS vulnerability.
3
What vulnerable software is affected by CVE-2014-4165?
CVE-2014-4165 affects ntop and the openSUSE versions 13.1 and 13.2.
4
What type of vulnerability is CVE-2014-4165?
CVE-2014-4165 is a cross-site scripting (XSS) vulnerability.
5
Who can exploit CVE-2014-4165?
Remote attackers can exploit CVE-2014-4165 to inject arbitrary web scripts or HTML.