Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 363885 - <net-analyzer/cacti-0.8.7h: Cross-site scripting vulnerability (CVE-2011-4824)
Summary: <net-analyzer/cacti-0.8.7h: Cross-site scripting vulnerability (CVE-2011-4824)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/44133/
Whiteboard: B4 [noglsa]
Keywords:
Depends on: 387661
Blocks:
  Show dependency tree
 
Reported: 2011-04-16 21:24 UTC by Tim Sammut (RETIRED)
Modified: 2012-01-11 06:55 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Tim Sammut (RETIRED) gentoo-dev 2011-04-16 21:24:52 UTC
From the third-party advisory at $URL:

Description

A vulnerability has been discovered in Cacti, which can be exploited by malicious people to conduct cross-site scripting attacks.

Input passed via the "drp_action" parameter to host.php (when "action" is set to "actions") is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

The vulnerability is confirmed in version 0.8.7g. Other versions may also be affected.

Solution

Fixed in the SVN repository.
Comment 1 Sean Amoss (RETIRED) gentoo-dev Security 2011-11-15 12:51:27 UTC
Issue is fixed in cacti 0.8.7h:
http://www.cacti.net/release_notes_0_8_7h.php

Stabilization of =net-analyzer/cacti-0.8.7h is underway in bug 387661
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2011-12-20 00:04:05 UTC
CVE-2011-4824 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4824):
  SQL injection vulnerability in auth_login.php in Cacti before 0.8.7h allows
  remote attackers to execute arbitrary SQL commands via the login_username
  parameter.
Comment 3 Tim Sammut (RETIRED) gentoo-dev 2012-01-11 06:55:10 UTC
Stabilization of fixed package was completed in bug 394595. Closing noglsa for XSS.