Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.100205
Category:Web application abuses
Title:Cacti < 0.8.7b 'data_input.php' XSS Vulnerability
Summary:Cacti is prone to a cross-site scripting (XSS) vulnerability; because the application fails to sufficiently sanitize user-supplied input.
Description:Summary:
Cacti is prone to a cross-site scripting (XSS) vulnerability
because the application fails to sufficiently sanitize user-supplied input.

Vulnerability Impact:
An attacker may leverage this issue to execute arbitrary script
code in the browser of an unsuspecting user in the context of the affected site. This may let the
attacker steal cookie-based authentication credentials and launch other attacks.

Affected Software/OS:
Cacti prior to version 0.8.7b.

Solution:
Update to version 0.8.7b or later.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2008-0783
BugTraq ID: 27749
http://www.securityfocus.com/bid/27749
BugTraq ID: 34991
http://www.securityfocus.com/bid/34991
Bugtraq: 20080212 Cacti 0.8.7a Multiple Vulnerabilities (Google Search)
http://www.securityfocus.com/archive/1/488018/100/0/threaded
Bugtraq: 20080212 cacti -- Multiple security vulnerabilities have been discovered (Google Search)
http://www.securityfocus.com/archive/1/488013/100/0/threaded
Debian Security Information: DSA-1569 (Google Search)
http://www.debian.org/security/2008/dsa-1569
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00570.html
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00593.html
http://security.gentoo.org/glsa/glsa-200803-18.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2008:052
http://www.securitytracker.com/id?1019414
http://secunia.com/advisories/28872
http://secunia.com/advisories/28976
http://secunia.com/advisories/29242
http://secunia.com/advisories/29274
http://secunia.com/advisories/30045
http://securityreason.com/securityalert/3657
SuSE Security Announcement: SUSE-SR:2008:005 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html
http://www.vupen.com/english/advisories/2008/0540
XForce ISS Database: cacti-datainput-xss(50575)
https://exchange.xforce.ibmcloud.com/vulnerabilities/50575
CopyrightCopyright (C) 2009 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.