Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2009-4032Cross-site Scripting in Cacti

CWE-79Cross-site Scripting13 documents7 sources
Severity
4.3MEDIUMNVD
EPSS
6.8%
top 8.68%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedNov 29
Latest updateMay 17

Description

Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) graph.php, (2) include/top_graph_header.php, (3) lib/html_form.php, and (4) lib/timespan_settings.php, as demonstrated by the (a) graph_end or (b) graph_start parameters to graph.php; (c) the date1 parameter in a tree action to graph_view.php; and the (d) page_refresh and (e) default_dual_pane_width parameters to graph_settings.php.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/cacti< cacti 0.8.7g-1 (bookworm)+1
Debiancacti/cacti< 0.8.7e-1.1+7
NVDcacti/cacti0.8.7f+37

Patches

🔴Vulnerability Details

4
GHSA
GHSA-h2p8-mfhp-r2rg: Cross-site scripting (XSS) vulnerability in include/top_graph_header2022-05-17
GHSA
GHSA-2chx-2wx9-x7f6: Multiple cross-site scripting (XSS) vulnerabilities in Cacti 02022-05-02
OSV
CVE-2010-2543: Cross-site scripting (XSS) vulnerability in include/top_graph_header2010-08-23
OSV
CVE-2009-4032: Multiple cross-site scripting (XSS) vulnerabilities in Cacti 02009-11-29

💥Exploits & PoCs

2
Exploit-DB
Cacti 0.8.7e - Multiple Vulnerabilities2009-11-26
Exploit-DB
Cacti 0.8.x - 'graph.php' Multiple Cross-Site Scripting Vulnerabilities2009-11-21

📋Vendor Advisories

4
Debian
CVE-2010-2543: cacti - Cross-site scripting (XSS) vulnerability in include/top_graph_header.php in Cact...2010
Red Hat
cacti: Multiple cross-site scripting flaws2009-11-21
Red Hat
cacti: Multiple cross-site scripting flaws2009-11-21
Debian
CVE-2009-4032: cacti - Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e allow remote...2009

💬Community

1
Bugzilla
CVE-2009-4032 CVE-2010-2543 cacti: Multiple cross-site scripting flaws2009-11-25