Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2009-4032 | First vendor Publication | 2009-11-29 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 4.3 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) graph.php, (2) include/top_graph_header.php, (3) lib/html_form.php, and (4) lib/timespan_settings.php, as demonstrated by the (a) graph_end or (b) graph_start parameters to graph.php; (c) the date1 parameter in a tree action to graph_view.php; and the (d) page_refresh and (e) default_dual_pane_width parameters to graph_settings.php. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4032 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') (CWE/SANS Top 25) |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
ExploitDB Exploits
id | Description |
---|---|
2009-11-26 | Cacti 0.8.7e: Multiple Security Issues |
OpenVAS Exploits
Date | Description |
---|---|
2010-08-30 | Name : Mandriva Update for cacti MDVSA-2010:160 (cacti) File : nvt/gb_mandriva_MDVSA_2010_160.nasl |
2010-01-15 | Name : Fedora Update for cacti FEDORA-2009-12560 File : nvt/gb_fedora_2009_12560_cacti_fc12.nasl |
2009-12-30 | Name : Debian Security Advisory DSA 1954-1 (cacti) File : nvt/deb_1954_1.nasl |
2009-12-30 | Name : Fedora Core 11 FEDORA-2009-12575 (cacti) File : nvt/fcore_2009_12575.nasl |
2009-11-25 | Name : Cacti Multiple HTML Injection Vulnerabilities File : nvt/cacti_37109.nasl |
2009-11-23 | Name : FreeBSD Ports: cacti File : nvt/freebsd_cacti6.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
60566 | Cacti graph.php Multiple Parameter XSS Cacti contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'graph_start' and 'graph_end' parameters upon submission to the graph.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server. |
60565 | Cacti include/top_graph_header.php Multiple Parameter XSS Cacti contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'page_refresh' and 'default_dual_pane_width' parameters upon submission to the include/top_graph_header.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server. |
60564 | Cacti lib/html_form.php Multiple Parameter XSS Cacti contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'name', 'value', 'form_previous_value' and 'array_display[id]' parameters upon submission to the lib/html_form.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server. |
60483 | Cacti lib/timespan_settings.php Multiple Parameter XSS Cacti contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the 'date1' and 'date2' parameters upon submission to the lib/timespan_settings.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-02-25 | Name : The remote Fedora host is missing a security update. File : fedora_2009-12560.nasl - Type : ACT_GATHER_INFO |
2010-02-24 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1954.nasl - Type : ACT_GATHER_INFO |
2009-12-28 | Name : The remote Fedora host is missing a security update. File : fedora_2009-12575.nasl - Type : ACT_GATHER_INFO |
2009-12-07 | Name : The remote openSUSE host is missing a security update. File : suse_11_0_cacti-091202.nasl - Type : ACT_GATHER_INFO |
2009-11-24 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_04104985d84611de84e400215af774f0.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:09:53 |
|
2024-11-28 12:20:15 |
|
2023-02-13 09:29:14 |
|
2023-02-02 21:28:54 |
|
2021-05-04 12:10:31 |
|
2021-04-22 01:10:58 |
|
2020-05-23 00:24:37 |
|
2018-10-11 00:19:43 |
|
2017-08-17 09:22:47 |
|
2016-12-28 09:21:54 |
|
2016-06-28 17:54:11 |
|
2016-04-26 19:16:13 |
|
2014-02-17 10:52:27 |
|
2013-05-11 00:01:26 |
|