Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2010-2543Cross-site Scripting in Cacti

Severity
4.3MEDIUMNVD
EPSS
10.5%
top 6.72%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedAug 23
Latest updateMay 17

Description

Cross-site scripting (XSS) vulnerability in include/top_graph_header.php in Cacti before 0.8.7g allows remote attackers to inject arbitrary web script or HTML via the graph_start parameter to graph.php. NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-4032.2.b.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/cacti< cacti 0.8.7g-1 (bookworm)
Debiancacti/cacti< 0.8.7g-1+3
NVDcacti/cacti0.8.7f+37

🔴Vulnerability Details

2
GHSA
GHSA-h2p8-mfhp-r2rg: Cross-site scripting (XSS) vulnerability in include/top_graph_header2022-05-17
OSV
CVE-2010-2543: Cross-site scripting (XSS) vulnerability in include/top_graph_header2010-08-23

💥Exploits & PoCs

1
Exploit-DB
Cacti 0.8.7e - Multiple Vulnerabilities2009-11-26

📋Vendor Advisories

2
Debian
CVE-2010-2543: cacti - Cross-site scripting (XSS) vulnerability in include/top_graph_header.php in Cact...2010
Red Hat
cacti: Multiple cross-site scripting flaws2009-11-21

💬Community

1
Bugzilla
CVE-2009-4032 CVE-2010-2543 cacti: Multiple cross-site scripting flaws2009-11-25