CVE-2015-2665Cross-site Scripting in Cacti

Severity
4.3MEDIUMNVD
EPSS
0.4%
top 37.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 17
Latest updateMay 17

Description

Cross-site scripting (XSS) vulnerability in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/cacti< cacti 0.8.8d+ds1-1 (bookworm)
Debiancacti/cacti< 0.8.8d+ds1-1+3
NVDcacti/cacti0.8.8c

Also affects: Fedora 22, 23, 24

🔴Vulnerability Details

2
GHSA
GHSA-g258-xc2f-gxcj: Cross-site scripting (XSS) vulnerability in Cacti before 02022-05-17
OSV
CVE-2015-2665: Cross-site scripting (XSS) vulnerability in Cacti before 02015-06-17

📋Vendor Advisories

1
Debian
CVE-2015-2665: cacti - Cross-site scripting (XSS) vulnerability in Cacti before 0.8.8d allows remote at...2015

💬Community

4
Bugzilla
CVE-2015-6792 chromium-browser: Fixes from internal audits and fuzzing2015-12-16
Bugzilla
CVE-2015-4454 CVE-2015-2665 cacti: various flaws [epel-all]2015-06-19
Bugzilla
CVE-2015-2665 cacti: Cross-site scripting (XSS) vulnerability2015-06-19
Bugzilla
CVE-2015-4454 CVE-2015-2665 cacti: various flaws [fedora-all]2015-06-19