First published: Thu Feb 14 2008(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote attackers to inject arbitrary web script or HTML via (1) the view_type parameter to graph.php; (2) the filter parameter to graph_view.php; (3) the action parameter to the draw_navigation_text function in lib/functions.php, reachable through index.php (aka the login page) or data_input.php; or (4) the login_username parameter to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti Cacti | =0.8.7 | |
Cacti Cacti | =0.8.5a | |
Cacti Cacti | =0.8.3 | |
Cacti Cacti | =0.8.2 | |
Cacti Cacti | =0.8.5 | |
Cacti Cacti | =0.8.7a | |
Cacti Cacti | =0.8.6f | |
Cacti Cacti | =0.8.6j | |
Cacti Cacti | =0.8 | |
Cacti Cacti | =0.8.6i | |
Cacti Cacti | =0.6.7 | |
Cacti Cacti | =0.8.1 | |
Cacti Cacti | =0.8.4 | |
Cacti Cacti | =0.8.6c | |
Cacti Cacti | =0.8.2a | |
Cacti Cacti | =0.8.3a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.