Cacti Cross Site Scripting and HTML Injection Vulnerabilities
BID:42575
Info
Cacti Cross Site Scripting and HTML Injection Vulnerabilities
| Bugtraq ID: | 42575 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-2544 CVE-2010-2545 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 19 2010 12:00AM |
| Updated: | Apr 13 2015 08:44PM |
| Credit: | <br>Marc Schoenefeld |
| Vulnerable: |
S.u.S.E. openSUSE 11.0 RedHat HPC Solution EL5 5 Planet Technology WSW-2401 0.8.6 h Planet Technology WSW-2401 0.8.6 g MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Cacti Cacti 0.8.7 Cacti Cacti 0.8.6 f Cacti Cacti 0.8.6 c Cacti Cacti 0.8.5 a Cacti Cacti 0.8.5 Cacti Cacti 0.8.4 Cacti Cacti 0.8.3 a Cacti Cacti 0.8.3 Cacti Cacti 0.8.2 a Cacti Cacti 0.8.2 Cacti Cacti 0.8.1 Cacti Cacti 0.8 Cacti Cacti 0.8.7f Cacti Cacti 0.8.7e Cacti Cacti 0.8.7d Cacti Cacti 0.8.7c Cacti Cacti 0.8.7b Cacti Cacti 0.8.7a Cacti Cacti 0.8.6k Cacti Cacti 0.8.6j Cacti Cacti 0.8.6i |
| Not Vulnerable: |
Cacti Cacti 0.8.7g |
Discussion
Cacti Cross Site Scripting and HTML Injection Vulnerabilities
Cacti is prone to cross-site-scripting and HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Versions prior to Cacti 0.8.7g are vulnerable.
Cacti is prone to cross-site-scripting and HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Versions prior to Cacti 0.8.7g are vulnerable.
Exploit / POC
Cacti Cross Site Scripting and HTML Injection Vulnerabilities
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
The following examples are available:
Cross-site scripting:
http://www.example.com/cacti/utilities.php?tail_lines=50&message_type=-1&go.x=10&go.y=9&refresh=20&reverse=1&filter=%22%3E%3Cscript%3Ealert%28document.cookie%29%3C%2Fscript%3E&page=1&action=view_logfile
HTML-injection:
<cacti>
<hash_000016fe5edd777a76d48fc48c11aded5211ef>
<name>
Unix - Load Average<![CDATA[<script>alert(document.cookie)</script>]]>
</name>
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
The following examples are available:
Cross-site scripting:
http://www.example.com/cacti/utilities.php?tail_lines=50&message_type=-1&go.x=10&go.y=9&refresh=20&reverse=1&filter=%22%3E%3Cscript%3Ealert%28document.cookie%29%3C%2Fscript%3E&page=1&action=view_logfile
HTML-injection:
<cacti>
<hash_000016fe5edd777a76d48fc48c11aded5211ef>
<name>
Unix - Load Average<![CDATA[<script>alert(document.cookie)</script>]]>
</name>
Solution / Fix
Cacti Cross Site Scripting and HTML Injection Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
MandrakeSoft Corporate Server 4.0
MandrakeSoft Corporate Server 4.0 x86_64
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva cacti-0.8.7g-0.1mdvmes5.1.noarch.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Enterprise Server 5
-
Mandriva cacti-0.8.7g-0.1mdvmes5.1.noarch.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0
-
Mandriva cacti-0.8.7g-0.1.20060mlcs4.noarch.rpm
http://www.mandriva.com/en/download/
MandrakeSoft Corporate Server 4.0 x86_64
-
Mandriva cacti-0.8.7g-0.1.20060mlcs4.noarch.rpm
http://www.mandriva.com/en/download/
References
Cacti Cross Site Scripting and HTML Injection Vulnerabilities
References:
References:
- Bug 459105 - CVE-2010-2544 (Cacti)
- Bug 459229 - CVE-2010-2545 (Cacti)
- Cacti Homepage (Cacti)