exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 5 of 5 RSS Feed

CVE-2008-0783

Status Candidate

Overview

Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote attackers to inject arbitrary web script or HTML via (1) the view_type parameter to graph.php; (2) the filter parameter to graph_view.php; (3) the action parameter to the draw_navigation_text function in lib/functions.php, reachable through index.php (aka the login page) or data_input.php; or (4) the login_username parameter to index.php.

Related Files

Debian Linux Security Advisory 1569-3
Posted Jul 16, 2008
Authored by Debian | Site debian.org

Debian Security Advisory 1569-3 - Since the previous security update, the cacti package could no longer be rebuilt from the source package. This update corrects that problem. Note that this problem does not affect regular use of the provided binary packages (.deb).

tags | advisory
systems | linux, debian
advisories | CVE-2008-0783, CVE-2008-0785
SHA-256 | dc36fff9689e4aaf063e726c1168b13fa138e673807e06ed013c70027925613e
Debian Linux Security Advisory 1569-2
Posted May 6, 2008
Authored by Debian | Site debian.org

Debian Security Advisory 1569-2 - The original update for cacti unfortunately introduced a regression. Updated packages have been created to address this. It was discovered that Cacti, a systems and services monitoring frontend, performed insufficient input sanitising, leading to cross site scripting and SQL injection being possible.

tags | advisory, xss, sql injection
systems | linux, debian
advisories | CVE-2008-0783, CVE-2008-0785
SHA-256 | a25d71e2a484bbe0525e22985604072f8a0b56a19f2fc79a50227fb2af5045fc
Debian Linux Security Advisory 1569-1
Posted May 5, 2008
Authored by Debian | Site debian.org

Debian Security Advisory 1569-1 - It was discovered that Cacti, a systems and services monitoring frontend, performed insufficient input sanitizing, leading to cross site scripting and SQL injection being possible.

tags | advisory, xss, sql injection
systems | linux, debian
advisories | CVE-2008-0783, CVE-2008-0785
SHA-256 | a15748a6e26762a361015640d77f7b3ebb8ef1199a358015d04400e2751b1fda
Gentoo Linux Security Advisory 200803-18
Posted Mar 13, 2008
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200803-18 - Multiple vulnerabilities were discovered in Cacti. Versions less than 0.8.7b are affected.

tags | advisory, vulnerability
systems | linux, gentoo
advisories | CVE-2008-0783, CVE-2008-0784, CVE-2008-0785, CVE-2008-0786
SHA-256 | 5d50dc8b0f98c436ce06069183ead19d0184212e2bf9f597effa4f50f1c1da86
Mandriva Linux Security Advisory 2008-052
Posted Feb 28, 2008
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory - A number of vulnerabilities were found in the Cacti program, including XSS vulnerabilities, SQL injection vulnerabilities, CRLF injection vulnerabilities, and information disclosure vulnerabilities.

tags | advisory, vulnerability, sql injection, info disclosure
systems | linux, mandriva
advisories | CVE-2008-0783, CVE-2008-0783, CVE-2008-0785, CVE-2008-0786
SHA-256 | 5fe42dda08bebbfce4119cc05d5717063b08de50a5bb53e8b466237a3065a788
Page 1 of 1
Back1Next

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close