CVE-2014-5025: XSS
Cross-site scripting (XSS) vulnerability in datasources.php in Cacti 0.8.8b allows remote authenticated users with console access to inject arbitrary web script or HTML via the namecache parameter in a dsedit action.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5025?
CVE-2014-5025 has a medium severity rating due to its ability to enable cross-site scripting attacks.
How do I fix CVE-2014-5025?
To fix CVE-2014-5025, update to the latest version of Cacti or apply the appropriate security patches provided by your OS vendor.
Who is affected by CVE-2014-5025?
CVE-2014-5025 affects remote authenticated users with console access in Cacti version 0.8.8b on specific Linux distributions.
What type of attack is possible with CVE-2014-5025?
CVE-2014-5025 allows attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.
Is there a known exploit for CVE-2014-5025?
Yes, CVE-2014-5025 has documented exploits that leverage the vulnerability to execute malicious scripts.