| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.100655 |
| Category: | Web application abuses |
| Title: | Cacti Multiple Cross Site Scripting Vulnerabilities |
| Summary: | Determine if installed Cacti version is vulnerable |
| Description: | Overview: Cacti is prone to multiple cross-site scripting vulnerabilities because the software fails to sufficiently sanitize user- supplied input An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks. Versions prior to Cacti 0.8.7f are vulnerable. Solution: Updates are available. Please see the references for details. References: http://www.securityfocus.com/bid/40332 http://cacti.net/ http://www.cacti.net/release_notes_0_8_7f.php http://www.securityfocus.com/archive/1/511393 |
| Cross-Ref: |
BugTraq ID: 40332 Common Vulnerability Exposure (CVE) ID: CVE-2010-1644 Bugtraq: 20100521 Cacti Multiple Parameter Cross Site Scripting Vulnerabilities (Google Search) http://www.securityfocus.com/archive/1/511393 http://www.mandriva.com/security/advisories?name=MDVSA-2010:160 RedHat Security Advisories: RHSA-2010:0635 https://rhn.redhat.com/errata/RHSA-2010-0635.html http://www.securityfocus.com/bid/40332 http://secunia.com/advisories/41041 http://www.vupen.com/english/advisories/2010/1203 http://www.vupen.com/english/advisories/2010/2132 |
| Copyright | This script is Copyright (C) 2010 Greenbone Networks GmbH |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|