PT-2014-6257 · Cacti+1 · Cacti+1

Published

2014-10-09

·

Updated

2024-06-15

·

CVE-2014-5025

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cacti version 0.8.8b
Description A cross-site scripting (XSS) issue exists, allowing remote authenticated users with console access to inject arbitrary web script or HTML via the name cache parameter in a "ds edit" action.
Recommendations For Cacti version 0.8.8b, as a temporary workaround, consider restricting access to the data sources.php file until a patch is available. Avoid using the name cache parameter in the affected ds edit action to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1467
CVE-2014-5025
DLA-40-1
DSA-3007-1
MGASA-2014-0403
OPENSUSE-SU-2024:10084-1

Affected Products

Alt Linux
Cacti