Cacti Multiple Cross Site Scripting Vulnerabilities
BID:40332
Info
Cacti Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 40332 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-1644 |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2010 12:00AM |
| Updated: | May 07 2015 05:06PM |
| Credit: | <br>Mohammed Boumediane from VUPEN Security |
| Vulnerable: |
Redhat HPC Solution EL5 5 Planet Technology WSW-2401 0.8.6 h Planet Technology WSW-2401 0.8.6 g MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Cacti Cacti 0.8.7 Cacti Cacti 0.8.6 f Cacti Cacti 0.8.6 c Cacti Cacti 0.8.5 a Cacti Cacti 0.8.5 Cacti Cacti 0.8.4 Cacti Cacti 0.8.3 a Cacti Cacti 0.8.3 Cacti Cacti 0.8.2 a Cacti Cacti 0.8.2 Cacti Cacti 0.8.1 Cacti Cacti 0.8 Cacti Cacti 0.6.7 Cacti Cacti 0.8.7f Cacti Cacti 0.8.7e Cacti Cacti 0.8.7d Cacti Cacti 0.8.7c Cacti Cacti 0.8.7b Cacti Cacti 0.8.7a Cacti Cacti 0.8.6k Cacti Cacti 0.8.6j Cacti Cacti 0.8.6i |
| Not Vulnerable: |
Cacti Cacti 0.8.7g |
Discussion
Cacti Multiple Cross Site Scripting Vulnerabilities
Cacti is prone to multiple cross-site scripting vulnerabilities because the software fails to sufficiently sanitize user-supplied input
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Cacti 0.8.7g are vulnerable.
Cacti is prone to multiple cross-site scripting vulnerabilities because the software fails to sufficiently sanitize user-supplied input
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to Cacti 0.8.7g are vulnerable.
Exploit / POC
Cacti Multiple Cross Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Cacti Multiple Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
MandrakeSoft Corporate Server 4.0
MandrakeSoft Corporate Server 4.0 x86_64
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva cacti-0.8.7g-0.1mdvmes5.1.noarch.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5
-
Mandriva cacti-0.8.7g-0.1mdvmes5.1.noarch.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0
-
Mandriva cacti-0.8.7g-0.1.20060mlcs4.noarch.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0 x86_64
-
Mandriva cacti-0.8.7g-0.1.20060mlcs4.noarch.rpm
http://www.mandriva.com/en/download/
References
Cacti Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Cacti Homepage (Cacti)
- Release Notes - 0.8.7g (cacti)
- Cacti Multiple Parameter Cross Site Scripting Vulnerabilities ("VUPEN Web Security"
)