VYPR
Unrated severityNVD Advisory· Published Aug 12, 2002· Updated Jun 16, 2026

CVE-2002-0412

CVE-2002-0412

Description

Format string vulnerability in TraceEvent function for ntop before 2.1 allows remote attackers to execute arbitrary code by causing format strings to be injected into calls to the syslog function, via (1) an HTTP GET request, (2) a user name in HTTP authentication, or (3) a password in HTTP authentication.

Affected products

2
  • Ntop/Ntop2 versions
    cpe:2.3:a:luca_deri:ntop:2.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:luca_deri:ntop:2.0:*:*:*:*:*:*:*
    • (no CPE)range: <2.1

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.