MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote attackers to inject arbitrary web script or HTML via (1) the view_type parameter to graph.php; (2) the filter parameter to graph_view.php; (3) the action parameter to the draw_navigation_text function in lib/functions.php, reachable through index.php (aka the login page) or data_input.php; or (4) the login_username parameter to index.php
Published Feb 14, 2008
4.3
MEDIUMCVSS 2.0
EPSS 5.25%
Description
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote attackers to inject arbitrary web script or HTML via (1) the view_type parameter to graph.php; (2) the filter parameter to graph_view.php; (3) the action parameter to the draw_navigation_text function in lib/functions.php, reachable through index.php (aka the login page) or data_input.php; or (4) the login_username parameter to index.php.
Affected products
No data.
OR
- 0.6.7
- 0.8
- 0.8.1
- 0.8.2
- 0.8.2a
- 0.8.3
- 0.8.3a
- 0.8.4
- 0.8.5
- 0.8.5a
- 0.8.6c
- 0.8.6f
- 0.8.6i
- 0.8.6j
- 0.8.7
- 0.8.7a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (23)
- http://bugs.cacti.net/view.php?id=1245 x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/28872 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/28976 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/29242 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/29274 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30045 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://security.gentoo.org/glsa/glsa-200803-18.xml vendor-advisoryx_refsource_GENTOO
- http://securityreason.com/securityalert/3657 third-party-advisoryx_refsource_SREASON
- http://www.cacti.net/release_notes_0_8_7b.php x_refsource_CONFIRMPatch
- http://www.debian.org/security/2008/dsa-1569 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:052 vendor-advisoryx_refsource_MANDRIVA
- http://www.securityfocus.com/archive/1/488013/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/488018/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/27749 vdb-entryx_refsource_BIDExploitPatch
- http://www.securityfocus.com/bid/34991 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1019414 vdb-entryx_refsource_SECTRACK
- http://www.vupen.com/english/advisories/2008/0540 vdb-entryx_refsource_VUPENVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=432758 x_refsource_CONFIRM
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2008-0790 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50575 vdb-entryx_refsource_XF
- https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00570.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00593.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 14, 2008
Updated Aug 7, 2024
Reserved Feb 14, 2008
Link CVE-2008-0783
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2008-0790 Assigner mitre
Published Feb 14, 2008
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2008-0790