ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the user cookie and username parameter to admin/password_reset.lua.
Software security is not security software. Here we're concerned with topics like authentication, access control, confidentiality, cryptography, and privilege management.
Link | Tags |
---|---|
http://packetstormsecurity.com/files/134593/ntop-ng-2.0.15102-Privilege-Escalation.html | exploit |
http://seclists.org/fulldisclosure/2015/Dec/10 | mailing list exploit |
https://www.exploit-db.com/exploits/38836/ | exploit |