CVE-2009-4032
Cacti 0.8.7e - Cross-Site Scripting via Multiple Parameters
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2009-4032. PoCs published by Moritz Naumann.
AI-analyzed exploit summary This exploit demonstrates multiple XSS vulnerabilities in Cacti versions prior to 0.8.7g by injecting malicious scripts via unsanitized input parameters in the graph.php file.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) graph.php, (2) include/top_graph_header.php, (3) lib/html_form.php, and (4) lib/timespan_settings.php, as demonstrated by the (a) graph_end or (b) graph_start parameters to graph.php; (c) the date1 parameter in a tree action to graph_view.php; and the (d) page_refresh and (e) default_dual_pane_width parameters to graph_settings.php.
Exploits (2)
This exploit demonstrates multiple XSS vulnerabilities in Cacti versions prior to 0.8.7g by injecting malicious scripts via unsanitized input parameters in the graph.php file.
This is a detailed technical writeup describing multiple XSS vulnerabilities and a privilege escalation issue in Cacti 0.8.7e and earlier. It includes proof-of-concept URLs and commands, as well as patch references.