CVE-2009-4032
Published: 29 November 2009
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) graph.php, (2) include/top_graph_header.php, (3) lib/html_form.php, and (4) lib/timespan_settings.php, as demonstrated by the (a) graph_end or (b) graph_start parameters to graph.php; (c) the date1 parameter in a tree action to graph_view.php; and the (d) page_refresh and (e) default_dual_pane_width parameters to graph_settings.php.
Notes
Author | Note |
---|---|
jdstrand | cross_site_fix.patch still not applied as of 0.8.7e-4 |
mdeslaur | patch is in fact in the lucid package |
Priority
Status
Package | Release | Status |
---|---|---|
cacti Launchpad, Ubuntu, Debian |
dapper |
Ignored
(end of life)
|
hardy |
Ignored
(end of life)
|
|
jaunty |
Ignored
(end of life)
|
|
karmic |
Ignored
(end of life)
|
|
lucid |
Not vulnerable
(0.8.7e-2)
|
|
maverick |
Released
(0.8.7g-1)
|
|
natty |
Released
(0.8.7g-1)
|
|
oneiric |
Released
(0.8.7g-1)
|
|
upstream |
Released
(0.8.7g-1)
|
|
Patches: upstream: http://www.cacti.net/download_patches.php upstream: http://www.cacti.net/downloads/patches/0.8.7e/cross_site_fix.patch |