Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.100213
Categoría:Web application abuses
Título:Cacti < 0.8.7b Multiple Input Validation Vulnerabilities
Resumen:Cacti is prone to multiple unspecified input-validation; vulnerabilities.
Descripción:Summary:
Cacti is prone to multiple unspecified input-validation
vulnerabilities.

Vulnerability Insight:
The following flaws exist:

- Multiple cross-site scripting vulnerabilities

- Multiple SQL-injection vulnerabilities

- An HTTP response-splitting vulnerability

Vulnerability Impact:
Attackers may exploit these vulnerabilities to influence or
misrepresent how web content is served, cached, or interpreted, to compromise the application, to
access or modify data, to exploit vulnerabilities in the underlying database, or to execute
arbitrary script code in the browser of an unsuspecting user.

Affected Software/OS:
Cacti version 0.8.7a and prior.

Solution:
Update to version 0.8.7b or later.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2008-0786
BugTraq ID: 27749
http://www.securityfocus.com/bid/27749
Bugtraq: 20080212 Cacti 0.8.7a Multiple Vulnerabilities (Google Search)
http://www.securityfocus.com/archive/1/488018/100/0/threaded
Bugtraq: 20080212 cacti -- Multiple security vulnerabilities have been discovered (Google Search)
http://www.securityfocus.com/archive/1/488013/100/0/threaded
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00570.html
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00593.html
http://security.gentoo.org/glsa/glsa-200803-18.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2008:052
http://www.securitytracker.com/id?1019414
http://secunia.com/advisories/28872
http://secunia.com/advisories/28976
http://secunia.com/advisories/29242
http://secunia.com/advisories/29274
http://securityreason.com/securityalert/3657
SuSE Security Announcement: SUSE-SR:2008:005 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html
http://www.vupen.com/english/advisories/2008/0540
Common Vulnerability Exposure (CVE) ID: CVE-2008-0785
Debian Security Information: DSA-1569 (Google Search)
http://www.debian.org/security/2008/dsa-1569
http://secunia.com/advisories/30045
Common Vulnerability Exposure (CVE) ID: CVE-2008-0784
Common Vulnerability Exposure (CVE) ID: CVE-2008-0783
BugTraq ID: 34991
http://www.securityfocus.com/bid/34991
XForce ISS Database: cacti-datainput-xss(50575)
https://exchange.xforce.ibmcloud.com/vulnerabilities/50575
CopyrightCopyright (C) 2009 Greenbone Networks GmbH

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.