CVE-2014-2326
published 2014-03-27CVE-2014-2326: Cross-site scripting (XSS) vulnerability in cdef.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to inject arbitrary web script or HTML via…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
3.22%
86.8th percentile
Cross-site scripting (XSS) vulnerability in cdef.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cacti | cacti | — | — |
| cacti | cacti | >= 0 < 0.8.8b+dfsg-4 | 0.8.8b+dfsg-4 |
| cacti | cacti | >= 0 < 0.8.8b+dfsg-4 | 0.8.8b+dfsg-4 |
| cacti | cacti | >= 0 < 0.8.8b+dfsg-4 | 0.8.8b+dfsg-4 |
| cacti | cacti | >= 0 < 0.8.8b+dfsg-4 | 0.8.8b+dfsg-4 |
| debian | cacti | < cacti 0.8.8b+dfsg-4 (bookworm) | cacti 0.8.8b+dfsg-4 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cacti 0.8.7g cross site scripting (ID 125849 / Nessus ID 73602)
vuldb·2026-05-09·CVSS 4.3
CVE-2014-2326 [MEDIUM] Cacti 0.8.7g cross site scripting (ID 125849 / Nessus ID 73602)
A vulnerability labeled as problematic has been found in Cacti 0.8.7g. Affected by this issue is some unknown functionality. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2014-2326. The attack may be launched remotely. There is no exploit available.
GHSA
GHSA-gpvp-6xwc-m44g: Cross-site scripting (XSS) vulnerability in cdef
ghsa_unreviewed·2022-05-14
CVE-2014-2326 [MEDIUM] CWE-79 GHSA-gpvp-6xwc-m44g: Cross-site scripting (XSS) vulnerability in cdef
Cross-site scripting (XSS) vulnerability in cdef.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
OSV
pcre3 vulnerabilities
osv·2015-07-29·CVSS 5.0
CVE-2014-8964 pcre3 vulnerabilities
pcre3 vulnerabilities
Michele Spagnuolo discovered that PCRE incorrectly handled certain regular
expressions. A remote attacker could use this issue to cause applications
using PCRE to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS. (CVE-2014-8964)
Kai Lu discovered that PCRE incorrectly handled certain regular
expressions. A remote attacker could use this issue to cause applications
using PCRE to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 15.04.
(CVE-2015-2325, CVE-2015-2326)
Wen Guanxing discovered that PCRE incorrectly handled certain regular
expressions. A remote attacker could use this issue to cause applications
using PCRE t
OSV
CVE-2014-2326: Cross-site scripting (XSS) vulnerability in cdef
osv·2014-03-27·CVSS 4.3
CVE-2014-2326 [MEDIUM] CVE-2014-2326: Cross-site scripting (XSS) vulnerability in cdef
Cross-site scripting (XSS) vulnerability in cdef.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Debian
CVE-2014-2326: cacti - Cross-site scripting (XSS) vulnerability in cdef.php in Cacti 0.8.7g, 0.8.8b, an...
vendor_debian·2014·CVSS 4.3
CVE-2014-2326 [MEDIUM] CVE-2014-2326: cacti - Cross-site scripting (XSS) vulnerability in cdef.php in Cacti 0.8.7g, 0.8.8b, an...
Cross-site scripting (XSS) vulnerability in cdef.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.8.8b+dfsg-4)
bullseye: resolved (fixed in 0.8.8b+dfsg-4)
forky: resolved (fixed in 0.8.8b+dfsg-4)
sid: resolved (fixed in 0.8.8b+dfsg-4)
trixie: resolved (fixed in 0.8.8b+dfsg-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-2327 CVE-2014-2326 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom [fedora-all]
bugzilla·2014-04-01·CVSS 4.3
CVE-2014-2327 [MEDIUM] CVE-2014-2327 CVE-2014-2326 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom [fedora-all]
CVE-2014-2327 CVE-2014-2326 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Bugzilla
CVE-2014-2327 CVE-2014-2326 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom [epel-all]
bugzilla·2014-04-01·CVSS 4.3
CVE-2014-2327 [MEDIUM] CVE-2014-2327 CVE-2014-2326 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom [epel-all]
CVE-2014-2327 CVE-2014-2326 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availabl
Bugzilla
CVE-2014-2326 CVE-2014-2327 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom
bugzilla·2014-03-28·CVSS 4.3
CVE-2014-2326 [MEDIUM] CVE-2014-2326 CVE-2014-2327 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom
CVE-2014-2326 CVE-2014-2327 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom
A posting to bugtraq from Deutsche Telekom [1] noted multiple flaws in Cacti 0.8.7g:
CVE-2014-2326: stored XSS
"The Cacti application is susceptible to stored XSS attacks. This is mainly the result of improper output encoding."
CVE-2014-2327: missing CSRF token
"The Cacti application does not implement any CSRF tokens. More about CSRF attacks, risks and mitigations see https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF). This attack has a vast impact on the security of the Cacti application, as multiple configuration parameters can be changed using a CSRF attack. One very critical attack vector is the modification of several binary files in the Cacti configuration, which may then b
http://bugs.cacti.net/view.php?id=2431http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131821.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-April/131842.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00034.htmlhttp://packetstormsecurity.com/files/125849/Deutsche-Telekom-CERT-Advisory-DTC-A-20140324-001.htmlhttp://secunia.com/advisories/57647http://secunia.com/advisories/59203http://svn.cacti.net/viewvc?view=rev&revision=7443http://www.debian.org/security/2014/dsa-2970http://www.securityfocus.com/archive/1/531588http://www.securityfocus.com/bid/66390https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742768https://security.gentoo.org/glsa/201509-03http://bugs.cacti.net/view.php?id=2431http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131821.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-April/131842.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00034.htmlhttp://packetstormsecurity.com/files/125849/Deutsche-Telekom-CERT-Advisory-DTC-A-20140324-001.htmlhttp://secunia.com/advisories/57647http://secunia.com/advisories/59203http://svn.cacti.net/viewvc?view=rev&revision=7443http://www.debian.org/security/2014/dsa-2970http://www.securityfocus.com/archive/1/531588http://www.securityfocus.com/bid/66390https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742768https://security.gentoo.org/glsa/201509-03
2014-03-27
Published