Unrated severityNVD Advisory· Published Aug 12, 2002· Updated Apr 16, 2026
CVE-2002-0412
CVE-2002-0412
Description
Format string vulnerability in TraceEvent function for ntop before 2.1 allows remote attackers to execute arbitrary code by causing format strings to be injected into calls to the syslog function, via (1) an HTTP GET request, (2) a user name in HTTP authentication, or (3) a password in HTTP authentication.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- www.iss.net/security_center/static/8347.phpnvdPatchVendor Advisory
- www.securityfocus.com/bid/4225nvdPatchVendor Advisory
- online.securityfocus.com/archive/1/259642nvdVendor Advisory
- archives.neohapsis.com/archives/vulnwatch/2002-q1/0056.htmlnvd
- listmanager.unipi.it/pipermail/ntop-dev/2002-February/000489.htmlnvd
- marc.infonvd
- marc.infonvd
- marc.infonvd
- snapshot.ntop.orgnvd
- www.osvdb.org/5307nvd
News mentions
0No linked articles in our index yet.