what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 5 of 5 RSS Feed

CVE-2008-0783

Status Candidate

Overview

Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote attackers to inject arbitrary web script or HTML via (1) the view_type parameter to graph.php; (2) the filter parameter to graph_view.php; (3) the action parameter to the draw_navigation_text function in lib/functions.php, reachable through index.php (aka the login page) or data_input.php; or (4) the login_username parameter to index.php.

Related Files

Debian Linux Security Advisory 1569-3
Posted Jul 16, 2008
Authored by Debian | Site debian.org

Debian Security Advisory 1569-3 - Since the previous security update, the cacti package could no longer be rebuilt from the source package. This update corrects that problem. Note that this problem does not affect regular use of the provided binary packages (.deb).

tags | advisory
systems | linux, debian
advisories | CVE-2008-0783, CVE-2008-0785
SHA-256 | dc36fff9689e4aaf063e726c1168b13fa138e673807e06ed013c70027925613e
Debian Linux Security Advisory 1569-2
Posted May 6, 2008
Authored by Debian | Site debian.org

Debian Security Advisory 1569-2 - The original update for cacti unfortunately introduced a regression. Updated packages have been created to address this. It was discovered that Cacti, a systems and services monitoring frontend, performed insufficient input sanitising, leading to cross site scripting and SQL injection being possible.

tags | advisory, xss, sql injection
systems | linux, debian
advisories | CVE-2008-0783, CVE-2008-0785
SHA-256 | a25d71e2a484bbe0525e22985604072f8a0b56a19f2fc79a50227fb2af5045fc
Debian Linux Security Advisory 1569-1
Posted May 5, 2008
Authored by Debian | Site debian.org

Debian Security Advisory 1569-1 - It was discovered that Cacti, a systems and services monitoring frontend, performed insufficient input sanitizing, leading to cross site scripting and SQL injection being possible.

tags | advisory, xss, sql injection
systems | linux, debian
advisories | CVE-2008-0783, CVE-2008-0785
SHA-256 | a15748a6e26762a361015640d77f7b3ebb8ef1199a358015d04400e2751b1fda
Gentoo Linux Security Advisory 200803-18
Posted Mar 13, 2008
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200803-18 - Multiple vulnerabilities were discovered in Cacti. Versions less than 0.8.7b are affected.

tags | advisory, vulnerability
systems | linux, gentoo
advisories | CVE-2008-0783, CVE-2008-0784, CVE-2008-0785, CVE-2008-0786
SHA-256 | 5d50dc8b0f98c436ce06069183ead19d0184212e2bf9f597effa4f50f1c1da86
Mandriva Linux Security Advisory 2008-052
Posted Feb 28, 2008
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory - A number of vulnerabilities were found in the Cacti program, including XSS vulnerabilities, SQL injection vulnerabilities, CRLF injection vulnerabilities, and information disclosure vulnerabilities.

tags | advisory, vulnerability, sql injection, info disclosure
systems | linux, mandriva
advisories | CVE-2008-0783, CVE-2008-0783, CVE-2008-0785, CVE-2008-0786
SHA-256 | 5fe42dda08bebbfce4119cc05d5717063b08de50a5bb53e8b466237a3065a788
Page 1 of 1
Back1Next

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close