CVE-2015-8368
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 5.1%
from disclosure to weapon0 days
Published on NVDDec 17
1st PoCDec 1
exploitation probability
5.1%top 9% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to admin/password_reset.lua.
Affected products
n/a · n/apublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/38836unverifiedcve_referencepacketstormsecurity.com/files/134593/ntop-ng-2.0.15102-Privilege-Escalation.htmlunverifiedcve_referencewww.exploit-db.com/exploits/38836/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.