CVE-2014-5464: XSS
Published Sep 8, 2014
·Updated
Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.
Affected Software
2 affected components
ntop ntopng<=1.2.0
ntop ntopng=1.1
Event History
Sep 8, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5464?
CVE-2014-5464 is classified as a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2014-5464?
To fix CVE-2014-5464, upgrade ntopng to version 1.2.1 or later.
3
What versions of ntopng are affected by CVE-2014-5464?
CVE-2014-5464 affects ntopng versions before 1.2.1, including 1.1 and up to 1.2.0.
4
What type of vulnerability is CVE-2014-5464?
CVE-2014-5464 is a cross-site scripting (XSS) vulnerability allowing remote script injection.
5
Who can exploit CVE-2014-5464?
Remote attackers can exploit CVE-2014-5464 by injecting arbitrary web scripts or HTML via the HTTP Host header.