Cacti Cross Site Scripting and HTML Injection Vulnerabilities
BID:62001
Info
Cacti Cross Site Scripting and HTML Injection Vulnerabilities
| Bugtraq ID: | 62001 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-5588 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 26 2013 12:00AM |
| Updated: | May 07 2015 05:12PM |
| Credit: | xistence |
| Vulnerable: |
S.u.S.E. openSUSE 13.1 S.u.S.E. openSUSE 12.3 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Cacti Cacti 0.8.7 Cacti Cacti 0.8.8b Cacti Cacti 0.8.8a Cacti Cacti 0.8.7i Cacti Cacti 0.8.7h Cacti Cacti 0.8.7g Cacti Cacti 0.8.7f Cacti Cacti 0.8.7e Cacti Cacti 0.8.7d Cacti Cacti 0.8.7c Cacti Cacti 0.8.7b Cacti Cacti 0.8.7a |
| Not Vulnerable: | |
Discussion
Cacti Cross Site Scripting and HTML Injection Vulnerabilities
Cacti is prone to cross-site-scripting and HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Cacti versions 0.8.8b and prior are vulnerable.
Cacti is prone to cross-site-scripting and HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Cacti versions 0.8.8b and prior are vulnerable.
Exploit / POC
Cacti Cross Site Scripting and HTML Injection Vulnerabilities
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
Cacti Cross Site Scripting and HTML Injection Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cacti Cross Site Scripting and HTML Injection Vulnerabilities
References:
References: