vendor:
NTOP-BOX
by:
Javuto
9,8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: NTOP-BOX
Affected Version From: 2.3
Affected Version To: 2.5
Patch Exists: YES
Related CWE: N/A
CPE: a:ntop:ntop_box
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2016
Remote Code Execution in NTOP-BOX Appliance
Multiple Remote Code Execution vulnerabilities were found in NTOP-BOX Appliance. These vulnerabilities can be exploited by sending specially crafted POST and GET requests to the vulnerable application. The issues were found originally in nbox 2.3 and confirmed in nbox 2.5.
Mitigation:
Upgrade to the latest version of NTOP-BOX Appliance