Summary
Cacti is prone to multiple multiple input-validation vulnerabilities including:
1. Multiple cross-site scripting vulnerabilities.
2. A cross-site request-forgery vulnerability.
3. An HTML-injection vulnerability.
An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, disclose or modify sensitive information, or perform unauthorized actions. Other attacks are also possible.
Versions prior to Cacti 0.8.7i are vulnerable.
Solution
Updates are available. Please see the references for more information.
References
Severity
Classification
-
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities
- Allegro RomPager HTTP Referer Header Cross Site Scripting Vulnerability
- Apache Struts Showcase Multiple Persistence Cross-Site Scripting Vulnerabilities
- Apache Tomcat Information Disclosure Vulnerability
- /cgi-bin directory browsable ?
- Advantech WebAccess Multiple Stack Based Buffer Overflow Vulnerabilities