ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to admin/password_reset.lua.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ntopng | Ntop | * | 2.0.151021 (including) |
Ntopng | Ubuntu | upstream | * |
Ntopng | Ubuntu | vivid | * |
Ntopng | Ubuntu | wily | * |