CVE Database
/

CVE-2014-4002

Back to search

CVE-2014-4002

Published: Jul 3, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the (1) drp_action parameter to cdef.php, (2) data_input.php, (3) data_queries.php, (4) data_sources.php, (5) data_templates.php, (6) graph_templates.php, (7) graphs.php, (8) host.php, or (9) host_templates.php or the (10) graph_template_input_id or (11) graph_template_id parameter to graph_templates_inputs.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

59203
third-party-advisory
x_refsource_SECUNIA
openSUSE-SU-2015:0479
vendor-advisory
x_refsource_SUSE
68257
vdb-entry
x_refsource_BID
DSA-2970
vendor-advisory
x_refsource_DEBIAN
GLSA-201509-03
vendor-advisory
x_refsource_GENTOO
59517
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now