SB2014061901 - Multiple vulnerabilities in ntop ntopng
Published: June 19, 2014 Updated: November 2, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Cross-site scripting (CVE-ID: CVE-2014-5464)
Vulnerability allows a remote attacker to perform Cross-site scripting attacks.
An input validation error exists in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 when processing HTTP Host header. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in victim's browser in security context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
2) Cross-site scripting (CVE-ID: CVE-2014-4329)
Vulnerability allows a remote attacker to perform Cross-site scripting attacks.
An input validation error exists in lua/host_details.lua in ntopng 1.1 when processing host parameter. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in victim's browser in security context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Remediation
Install update from vendor's website.
References
- http://osvdb.org/show/osvdb/110437
- http://packetstormsecurity.com/files/127995/ntopng-1.2.0-Cross-Site-Scripting.html
- http://seclists.org/fulldisclosure/2014/Aug/65
- http://seclists.org/fulldisclosure/2014/Sep/22
- http://seclists.org/fulldisclosure/2014/Sep/28
- http://secunia.com/advisories/60096
- http://www.exploit-db.com/exploits/34419
- http://www.ntop.org/ndpi/released-ndpi-1-5-1-and-ntopng-1-2-1/
- http://www.securityfocus.com/archive/1/533222/100/0/threaded
- http://www.securityfocus.com/archive/1/533332/100/0/threaded
- http://www.securityfocus.com/bid/69385
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95461
- http://packetstormsecurity.com/files/127329/Ntop-NG-1.1-Cross-Site-Scripting.html
- http://www.securityfocus.com/bid/66456
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92135
- https://svn.ntop.org/bugzilla/show_bug.cgi?id=379