CVE Database
/

CVE-2010-2545

Back to search

CVE-2010-2545

Published: Aug 23, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0.8.7g, as used in Red Hat High Performance Computing (HPC) Solution and other products, allow remote attackers to inject arbitrary web script or HTML via (1) the name element in an XML template to templates_import.php; and allow remote authenticated administrators to inject arbitrary web script or HTML via vectors related to (2) cdef.php, (3) data_input.php, (4) data_queries.php, (5) data_sources.php, (6) data_templates.php, (7) gprint_presets.php, (8) graph.php, (9) graphs_new.php, (10) graphs.php, (11) graph_templates_inputs.php, (12) graph_templates_items.php, (13) graph_templates.php, (14) graph_view.php, (15) host.php, (16) host_templates.php, (17) lib/functions.php, (18) lib/html_form.php, (19) lib/html_form_template.php, (20) lib/html.php, (21) lib/html_tree.php, (22) lib/rrd.php, (23) rra.php, (24) tree.php, and (25) user_admin.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

MDVSA-2010:160
vendor-advisory
x_refsource_MANDRIVA
42575
vdb-entry
x_refsource_BID
41041
third-party-advisory
x_refsource_SECUNIA
RHSA-2010:0635
vendor-advisory
x_refsource_REDHAT
ADV-2010-2132
vdb-entry
x_refsource_VUPEN
cacti-templatesimport-xss(61227)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now