CVE-2009-4032
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e allow remote attackers to inject arbitrary web script or HTML via vectors related to (1)...
- Published
- Nov 27, 2009
- Updated
- Aug 7, 2024
- Assigning CNA
- redhat
- Evidence observed
- Nov 21, 2009
Primary CVSS
nvd · CVSS 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:NLow · next 30 days
- Percentile
- 92.8%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) graph.php, (2) include/top_graph_header.php, (3) lib/html_form.php, and (4) lib/timespan_settings.php, as demonstrated by the (a) graph_end or (b) graph_start parameters to graph.php; (c) the date1 parameter in a tree action to graph_view.php; and the (d) page_refresh and (e) default_dual_pane_width parameters to graph_settings.php.
Sources
2Moritz Naumann · php · Nov 26, 2009
Moritz Naumann · php · Nov 21, 2009
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.