CVE-2010-2544: XSS
Cross-site scripting (XSS) vulnerability in utilities.php in Cacti before 0.8.7g, as used in Red Hat High Performance Computing (HPC) Solution and other products, allows remote attackers to inject arbitrary web script or HTML via the filter parameter.
Other sources
Summary:
Cross Site Scripting in parameter 'filter'
to reproduce:
/cacti/utilities.php?taillines=50&messagetype=-1&go.x=10&go.y=9&refresh=20&reverse=1&filter=%22%3E%3Cscript%3Ealert%28document.cookie%29%3C%2Fscript%3E&page=1&action=viewlogfile
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2544?
CVE-2010-2544 has been classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2010-2544?
To fix CVE-2010-2544, upgrade to Cacti version 0.8.7g or later.
Which software versions are vulnerable to CVE-2010-2544?
CVE-2010-2544 affects Cacti versions prior to 0.8.7g, including versions 0.5 to 0.8.7f.
Can CVE-2010-2544 be exploited remotely?
Yes, CVE-2010-2544 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.
What are the consequences of exploiting CVE-2010-2544?
Exploiting CVE-2010-2544 may allow attackers to execute malicious scripts in the context of the user's browser, potentially compromising user data.