VDB
CVE-2008-0783
CVE-2008-0783
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote attackers to inject arbitrary web script or HTML via (1) the view_type parameter to graph.php; (2) the filter parameter to graph_view.php; (3) the action parameter to the draw_navigation_text function in lib/functions.php, reachable through index.php (aka the login page) or data_input.php; or (4) the login_username parameter to index.php.
EPSS 3.84% · 88.4th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
3.84%
88.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| cacti | cacti | 0.6.7, 0.8, 0.8.3 |
Timeline
- Feb 14, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- http://secunia.com/advisories/29242 advisory
- FEDORA-2008-1737 vendor-advisory
- cacti-datainput-xss(50575) vdb
- http://bugs.cacti.net/view.php?id=1245 url
- https://bugzilla.redhat.com/show_bug.cgi?id=432758 url
- 3657 third-party-advisory
- SUSE-SR:2008:005 vendor-advisory
- GLSA-200803-18 vendor-advisory
- 28872 third-party-advisory
- MDVSA-2008:052 vendor-advisory
- http://www.cacti.net/release_notes_0_8_7b.php url
- 30045 third-party-advisory
- 29274 third-party-advisory
- 20080212 cacti -- Multiple security vulnerabilities have been discovered mailing-list
- ADV-2008-0540 vdb
- 27749 vdb
- DSA-1569 vendor-advisory
- 28976 third-party-advisory
- FEDORA-2008-1699 vendor-advisory
- 1019414 vdb
…and 3 more