First published: Thu Feb 14 2008(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote attackers to inject arbitrary web script or HTML via (1) the view_type parameter to graph.php; (2) the filter parameter to graph_view.php; (3) the action parameter to the draw_navigation_text function in lib/functions.php, reachable through index.php (aka the login page) or data_input.php; or (4) the login_username parameter to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti | =0.8.7 | |
Cacti | =0.8.5a | |
Cacti | =0.8.3 | |
Cacti | =0.8.2 | |
Cacti | =0.8.5 | |
Cacti | =0.8.7a | |
Cacti | =0.8.6f | |
Cacti | =0.8.6j | |
Cacti | =0.8 | |
Cacti | =0.8.6i | |
Cacti | =0.6.7 | |
Cacti | =0.8.1 | |
Cacti | =0.8.4 | |
Cacti | =0.8.6c | |
Cacti | =0.8.2a | |
Cacti | =0.8.3a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-0783 is typically rated as high due to its potential for cross-site scripting attacks.
To fix CVE-2008-0783, upgrade to Cacti version 0.8.7b or later.
CVE-2008-0783 affects Cacti versions prior to 0.8.7b, including 0.8.7, 0.8.6, and earlier.
Yes, CVE-2008-0783 can be exploited remotely by attackers to inject malicious scripts.
The vulnerable components in CVE-2008-0783 include graph.php and graph_view.php, specifically the view_type and filter parameters.