CVE-2010-1644
published 2010-08-23CVE-2010-1644: Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.86%
77.1th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products, allow remote attackers to inject arbitrary web script or HTML via the (1) hostname or (2) description parameter to host.php, or (3) the host_id parameter to data_sources.php.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cacti | cacti | <= 0.8.7e | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cacti: XSS issues in host.php and data_sources.php (VUPEN/ADV-2010-1203)
vendor_redhat·2010-05-20·CVSS 4.3
CVE-2010-1644 [MEDIUM] CWE-79 cacti: XSS issues in host.php and data_sources.php (VUPEN/ADV-2010-1203)
cacti: XSS issues in host.php and data_sources.php (VUPEN/ADV-2010-1203)
Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products, allow remote attackers to inject arbitrary web script or HTML via the (1) hostname or (2) description parameter to host.php, or (3) the host_id parameter to data_sources.php.
Debian
CVE-2010-1644: cacti - Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0.8.7f, as u...
vendor_debian·2010·CVSS 4.3
CVE-2010-1644 [MEDIUM] CVE-2010-1644: cacti - Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0.8.7f, as u...
Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products, allow remote attackers to inject arbitrary web script or HTML via the (1) hostname or (2) description parameter to host.php, or (3) the host_id parameter to data_sources.php.
Scope: local
bookworm: resolved (fixed in 0.8.7g-1)
bullseye: resolved (fixed in 0.8.7g-1)
forky: resolved (fixed in 0.8.7g-1)
sid: resolved (fixed in 0.8.7g-1)
trixie: resolved (fixed in 0.8.7g-1)
GHSA
GHSA-5882-82vc-8f56: Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0
ghsa_unreviewed·2022-05-17
CVE-2010-1644 [MEDIUM] CWE-79 GHSA-5882-82vc-8f56: Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0
Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products, allow remote attackers to inject arbitrary web script or HTML via the (1) hostname or (2) description parameter to host.php, or (3) the host_id parameter to data_sources.php.
OSV
CVE-2010-1644: Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0
osv·2010-08-23·CVSS 4.3
CVE-2010-1644 [MEDIUM] CVE-2010-1644: Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0
Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products, allow remote attackers to inject arbitrary web script or HTML via the (1) hostname or (2) description parameter to host.php, or (3) the host_id parameter to data_sources.php.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-1644 cacti: XSS issues in host.php and data_sources.php (VUPEN/ADV-2010-1203)
bugzilla·2010-06-29·CVSS 4.3
CVE-2010-1644 [MEDIUM] CVE-2010-1644 cacti: XSS issues in host.php and data_sources.php (VUPEN/ADV-2010-1203)
CVE-2010-1644 cacti: XSS issues in host.php and data_sources.php (VUPEN/ADV-2010-1203)
Multiple XSS issues were discovered in Cacti and fixed in version 0.8.7f:
- host.php via "hostname" and "description" parameters
- data_sources.php via "host_id" parameter
References:
http://www.vupen.com/english/advisories/2010/1203
http://www.cacti.net/release_notes_0_8_7f.php
Upstream commit:
http://svn.cacti.net/viewvc?view=rev&revision=5901
Discussion:
This issue has been addressed in following products:
Red Hat HPC Solution for RHEL 5
Via RHSA-2010:0635 https://rhn.redhat.com/errata/RHSA-2010-0635.html
Bugzilla
CVE-2010-1644 CVE-2010-1645 CVE-2010-2092 Cacti v0.8.7f - three security fixes
bugzilla·2010-05-24·CVSS 4.3
CVE-2010-1644 [MEDIUM] CVE-2010-1644 CVE-2010-1645 CVE-2010-2092 Cacti v0.8.7f - three security fixes
CVE-2010-1644 CVE-2010-1645 CVE-2010-2092 Cacti v0.8.7f - three security fixes
Cacti upstream has released:
[1] http://www.cacti.net/release_notes_0_8_7f.php
latest v0.8.7 version, addressing three security flaws:
[A], MOPS-2010-023: Cacti Graph Viewer SQL Injection Vulnerability
[2] http://php-security.org/2010/05/13/mops-2010-023-cacti-graph-viewer-sql-injection-vulnerability/index.html
[3] http://www.vupen.com/english/advisories/2010/1204
Credit: The vulnerability was discovered by Stefan Esser as part
of the SQL Injection Marathon.
Upstream changeset:
[4] http://svn.cacti.net/viewvc?view=rev&revision=5920
[B], Cross-site scripting issues reported by VUPEN Security
(http://www.vupen.com)
[5] http://www.vupen.com/english/advisories/2010/1203
Credit: Vulnerabilities reported by Moham
http://secunia.com/advisories/41041http://svn.cacti.net/viewvc?view=rev&revision=5901http://www.cacti.net/release_notes_0_8_7f.phphttp://www.mandriva.com/security/advisories?name=MDVSA-2010:160http://www.securityfocus.com/archive/1/511393http://www.securityfocus.com/bid/40332http://www.vupen.com/english/advisories/2010/1203http://www.vupen.com/english/advisories/2010/2132https://bugzilla.redhat.com/show_bug.cgi?id=609093https://rhn.redhat.com/errata/RHSA-2010-0635.htmlhttp://secunia.com/advisories/41041http://svn.cacti.net/viewvc?view=rev&revision=5901http://www.cacti.net/release_notes_0_8_7f.phphttp://www.mandriva.com/security/advisories?name=MDVSA-2010:160http://www.securityfocus.com/archive/1/511393http://www.securityfocus.com/bid/40332http://www.vupen.com/english/advisories/2010/1203http://www.vupen.com/english/advisories/2010/2132https://bugzilla.redhat.com/show_bug.cgi?id=609093https://rhn.redhat.com/errata/RHSA-2010-0635.html
2010-08-23
Published