Summary
Cacti is prone to multiple multiple input-validation vulnerabilities including:
1. Multiple cross-site scripting vulnerabilities.
2. A cross-site request-forgery vulnerability.
3. An HTML-injection vulnerability.
An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, disclose or modify sensitive information, or perform unauthorized actions. Other attacks are also possible.
Versions prior to Cacti 0.8.7i are vulnerable.
Solution
Updates are available. Please see the references for more information.
References
Severity
Classification
-
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities
- @Mail 'MailType' Parameter Cross Site Scripting Vulnerability
- 11in1 Cross Site Request Forgery and Local File Include Vulnerabilities
- 12Planet Chat Server one2planet.infolet.InfoServlet XSS
- 1024 CMS 1.1.0 Beta 'force_download.php' Local File Include Vulnerability
- Apache Continuum Cross Site Scripting Vulnerability