CVE-2008-0783
Cacti 0.8.7 - 'graph_view.php?filter' Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote attackers to inject arbitrary web script or HTML via (1) the view_type parameter to graph.php; (2) the filter parameter to graph_view.php; (3) the action parameter to the draw_navigation_text function in lib/functions.php, reachable through index.php (aka the login page) or data_input.php; or (4) the login_username parameter to index.php.
Múltiples vulnerabilidades de tipo cross-site scripting (XSS) en Cacti versión 0.8.7 anterior a 0.8.7b y versión 0.8.6 anterior a 0.8.6k, permiten a los atacantes remotos inyectar script web o HTML arbitrario por medio de (1) el parámetro view_type en el archivo graph.php; (2) el parámetro filter en el archivo graph_view.php; (3) el parámetro action en la función draw_navigation_text en el archivo lib/functions.php, accesible por medio del archivo index.php (también conocido como la página de inicio de sesión) o el archivo data_input.php; o (4) el parámetro login_username en el archivo index.php.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-02-12 First Exploit
- 2008-02-14 CVE Reserved
- 2008-02-14 CVE Published
- 2024-08-07 CVE Updated
- 2024-11-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (24)
URL | Tag | Source |
---|---|---|
http://bugs.cacti.net/view.php?id=1245 | X_refsource_confirm | |
http://secunia.com/advisories/29274 | Third Party Advisory | |
http://securityreason.com/securityalert/3657 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/488013/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/488018/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/34991 | Vdb Entry | |
http://www.securitytracker.com/id?1019414 | Vdb Entry | |
https://bugzilla.redhat.com/show_bug.cgi?id=432758 | X_refsource_confirm | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/50575 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/31158 | 2008-02-12 | |
https://www.exploit-db.com/exploits/31157 | 2008-02-12 | |
http://www.securityfocus.com/bid/27749 | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://www.cacti.net/release_notes_0_8_7b.php | 2018-10-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cacti Search vendor "Cacti" | Cacti Search vendor "Cacti" for product "Cacti" | 0.6.7 Search vendor "Cacti" for product "Cacti" and version "0.6.7" | - |
Affected
| ||||||
Cacti Search vendor "Cacti" | Cacti Search vendor "Cacti" for product "Cacti" | 0.8 Search vendor "Cacti" for product "Cacti" and version "0.8" | - |
Affected
| ||||||
Cacti Search vendor "Cacti" | Cacti Search vendor "Cacti" for product "Cacti" | 0.8.1 Search vendor "Cacti" for product "Cacti" and version "0.8.1" | - |
Affected
| ||||||
Cacti Search vendor "Cacti" | Cacti Search vendor "Cacti" for product "Cacti" | 0.8.2 Search vendor "Cacti" for product "Cacti" and version "0.8.2" | - |
Affected
| ||||||
Cacti Search vendor "Cacti" | Cacti Search vendor "Cacti" for product "Cacti" | 0.8.2a Search vendor "Cacti" for product "Cacti" and version "0.8.2a" | - |
Affected
| ||||||
Cacti Search vendor "Cacti" | Cacti Search vendor "Cacti" for product "Cacti" | 0.8.3 Search vendor "Cacti" for product "Cacti" and version "0.8.3" | - |
Affected
| ||||||
Cacti Search vendor "Cacti" | Cacti Search vendor "Cacti" for product "Cacti" | 0.8.3a Search vendor "Cacti" for product "Cacti" and version "0.8.3a" | - |
Affected
| ||||||
Cacti Search vendor "Cacti" | Cacti Search vendor "Cacti" for product "Cacti" | 0.8.4 Search vendor "Cacti" for product "Cacti" and version "0.8.4" | - |
Affected
| ||||||
Cacti Search vendor "Cacti" | Cacti Search vendor "Cacti" for product "Cacti" | 0.8.5 Search vendor "Cacti" for product "Cacti" and version "0.8.5" | - |
Affected
| ||||||
Cacti Search vendor "Cacti" | Cacti Search vendor "Cacti" for product "Cacti" | 0.8.5a Search vendor "Cacti" for product "Cacti" and version "0.8.5a" | - |
Affected
| ||||||
Cacti Search vendor "Cacti" | Cacti Search vendor "Cacti" for product "Cacti" | 0.8.6c Search vendor "Cacti" for product "Cacti" and version "0.8.6c" | - |
Affected
| ||||||
Cacti Search vendor "Cacti" | Cacti Search vendor "Cacti" for product "Cacti" | 0.8.6f Search vendor "Cacti" for product "Cacti" and version "0.8.6f" | - |
Affected
| ||||||
Cacti Search vendor "Cacti" | Cacti Search vendor "Cacti" for product "Cacti" | 0.8.6i Search vendor "Cacti" for product "Cacti" and version "0.8.6i" | - |
Affected
| ||||||
Cacti Search vendor "Cacti" | Cacti Search vendor "Cacti" for product "Cacti" | 0.8.6j Search vendor "Cacti" for product "Cacti" and version "0.8.6j" | - |
Affected
| ||||||
Cacti Search vendor "Cacti" | Cacti Search vendor "Cacti" for product "Cacti" | 0.8.7 Search vendor "Cacti" for product "Cacti" and version "0.8.7" | - |
Affected
| ||||||
Cacti Search vendor "Cacti" | Cacti Search vendor "Cacti" for product "Cacti" | 0.8.7a Search vendor "Cacti" for product "Cacti" and version "0.8.7a" | - |
Affected
|