CVE-2010-2543
Cacti < 0.8.7g - Cross-Site Scripting via graph_start Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-2543. PoCs published by Moritz Naumann.
AI-analyzed exploit summary This is a detailed technical writeup describing multiple XSS vulnerabilities and a privilege escalation issue in Cacti 0.8.7e and earlier. It includes proof-of-concept URLs and commands, as well as patch references.
Description
Cross-site scripting (XSS) vulnerability in include/top_graph_header.php in Cacti before 0.8.7g allows remote attackers to inject arbitrary web script or HTML via the graph_start parameter to graph.php. NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-4032.2.b.
Exploits (1)
This is a detailed technical writeup describing multiple XSS vulnerabilities and a privilege escalation issue in Cacti 0.8.7e and earlier. It includes proof-of-concept URLs and commands, as well as patch references.