{"id":"MGASA-2015-0168","summary":"Updated ntop packages fix CVE-2014-4165","details":"Updated ntop package fixes security vulnerability:\n\nLack of filtering in the title parameter of links to rrdPlugin allowed\ncross-site-scripting (XSS) attacks against users of the web interface\n(CVE-2014-4165).\n","modified":"2026-04-16T06:24:15.192868120Z","published":"2015-04-23T21:14:25Z","upstream":["CVE-2014-4165"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2015-0168.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=15723"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-updates/2015-04/msg00029.html"}],"affected":[{"package":{"name":"ntop","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/ntop?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.0.1-4.1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0168.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}