Back
CVE-2002-0412
Format string vulnerability in TraceEvent function for ntop before 2.1 allows remote attackers to execute arbitrary code by causing format strings to be injected into calls to the syslog function, via (1) an HTTP GET request, (2) a user name in HTTP authentication, or (3) a password in HTTP authentication.
Published: Aug 12, 2002
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| luca_deri | ntop | 2.0 |
GitHub Security Advisory GHSA-p6f9-rfgm-p6mf
Format string vulnerability in TraceEvent function for ntop before 2.1 allows remote attackers to...
References (20)
- http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0056.html
- http://listmanager.unipi.it/pipermail/ntop-dev/2002-February/000489.html
- http://marc.info/?l=bugtraq&m=101854261030453&w=2
- http://marc.info/?l=bugtraq&m=101856541322245&w=2
- http://marc.info/?l=bugtraq&m=101908224609740&w=2
- http://online.securityfocus.com/archive/1/259642 Vendor Advisory
- http://snapshot.ntop.org/
- http://www.iss.net/security_center/static/8347.php Patch, Vendor Advisory
- http://www.osvdb.org/5307
- http://www.securityfocus.com/bid/4225 Patch, Vendor Advisory
- http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0056.html
- http://listmanager.unipi.it/pipermail/ntop-dev/2002-February/000489.html
- http://marc.info/?l=bugtraq&m=101854261030453&w=2
- http://marc.info/?l=bugtraq&m=101856541322245&w=2
- http://marc.info/?l=bugtraq&m=101908224609740&w=2
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
4.17%
Top 10% most likely to be exploited
Threat Score
31.3 / 100
Data Sources
NVD
EPSS
GitHub