Back

CVE-2002-0412

Format string vulnerability in TraceEvent function for ntop before 2.1 allows remote attackers to execute arbitrary code by causing format strings to be injected into calls to the syslog function, via (1) an HTTP GET request, (2) a user name in HTTP authentication, or (3) a password in HTTP authentication.

Published: Aug 12, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
luca_deri ntop 2.0

GitHub Security Advisory GHSA-p6f9-rfgm-p6mf

Format string vulnerability in TraceEvent function for ntop before 2.1 allows remote attackers to...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 4.17%

Top 10% most likely to be exploited

Threat Score 31.3 / 100

Data Sources

NVD EPSS GitHub