Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2010-2545 | First vendor Publication | 2010-08-23 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 4.3 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0.8.7g, as used in Red Hat High Performance Computing (HPC) Solution and other products, allow remote attackers to inject arbitrary web script or HTML via (1) the name element in an XML template to templates_import.php; and allow remote authenticated administrators to inject arbitrary web script or HTML via vectors related to (2) cdef.php, (3) data_input.php, (4) data_queries.php, (5) data_sources.php, (6) data_templates.php, (7) gprint_presets.php, (8) graph.php, (9) graphs_new.php, (10) graphs.php, (11) graph_templates_inputs.php, (12) graph_templates_items.php, (13) graph_templates.php, (14) graph_view.php, (15) host.php, (16) host_templates.php, (17) lib/functions.php, (18) lib/html_form.php, (19) lib/html_form_template.php, (20) lib/html.php, (21) lib/html_tree.php, (22) lib/rrd.php, (23) rra.php, (24) tree.php, and (25) user_admin.php. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2545 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') (CWE/SANS Top 25) |
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2012-02-12 | Name : Debian Security Advisory DSA 2384-2 (cacti) File : nvt/deb_2384_2.nasl |
2012-02-11 | Name : Debian Security Advisory DSA 2384-1 (cacti) File : nvt/deb_2384_1.nasl |
2010-08-30 | Name : Cacti Cross Site Scripting and HTML Injection Vulnerabilities File : nvt/gb_cacti_42575.nasl |
2010-08-30 | Name : Mandriva Update for cacti MDVSA-2010:160 (cacti) File : nvt/gb_mandriva_MDVSA_2010_160.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
67529 | Cacti user_admin.php Unspecified Parameter XSS |
67528 | Cacti tree.php Unspecified Parameter XSS |
67527 | Cacti rra.php Unspecified Parameter XSS |
67526 | Cacti lib/rrd.php Unspecified Parameter XSS |
67525 | Cacti lib/html_tree.php Unspecified Parameter XSS |
67524 | Cacti lib/html.php Unspecified Parameter XSS |
67523 | Cacti lib/html_form_template.php Unspecified Parameter XSS |
67522 | Cacti lib/html_form.php Unspecified Parameter XSS |
67521 | Cacti lib/functions.php Unspecified Parameter XSS |
67520 | Cacti host_templates.php Unspecified Parameter XSS |
67519 | Cacti host.php Unspecified Parameter XSS |
67518 | Cacti graph_view.php Unspecified Parameter XSS |
67517 | Cacti graph_templates.php Unspecified Parameter XSS |
67516 | Cacti graph_templates_items.php Unspecified Parameter XSS |
67515 | Cacti graph_templates_inputs.php Unspecified Parameter XSS |
67514 | Cacti graphs.php Unspecified Parameter XSS |
67513 | Cacti graphs_new.php Unspecified Parameter XSS |
67512 | Cacti graph.php Unspecified Parameter XSS |
67511 | Cacti gprint_presets.php Unspecified Parameter XSS |
67510 | Cacti data_templates.php Unspecified Parameter XSS |
67509 | Cacti data_sources.php Unspecified Parameter XSS |
67508 | Cacti data_queries.php Unspecified Parameter XSS |
67507 | Cacti data_input.php Unspecified Parameter XSS |
67506 | Cacti cdef.php Unspecified Parameter XSS |
67505 | Cacti templates_import.php XML Template name Element XSS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2014-01-22 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201401-20.nasl - Type : ACT_GATHER_INFO |
2012-01-20 | Name : The remote web server is running a PHP application that is affected by multip... File : cacti_087g.nasl - Type : ACT_GATHER_INFO |
2012-01-12 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2384.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:07:47 |
|
2024-11-28 12:22:20 |
|
2023-02-13 09:29:09 |
|
2023-02-02 21:28:52 |
|
2021-05-05 01:07:08 |
|
2021-05-04 12:11:48 |
|
2021-04-22 01:12:22 |
|
2020-05-23 01:42:18 |
|
2020-05-23 00:26:04 |
|
2017-08-17 09:23:03 |
|
2016-04-26 19:56:08 |
|
2014-02-17 10:56:14 |
|
2013-05-10 23:28:22 |
|