oss-sec mailing list archives
Re: CVE request: cacti XSS
From: cve-assign () mitre org
Date: Tue, 22 Jul 2014 16:07:49 -0400 (EDT)
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
http://bugs.cacti.net/view.php?id=2456
Product Version 0.8.8b
You need console access to create any of these items, but you don't need full administrator privileges.
(One of the vectors reported by flekyy was separately disclosed a week before the others reported by flekyy.)
Add a new Data Source with the following name: [XSS] -- Browse to http://<IP>/cacti/data_sources.php [^] and you'll see a popup with the text "XSS"
Use CVE-2014-5025.
- If you create a Graph Tree with Title: [XSS] - If you create a CDEF with Name: [XSS] - If you create a Data Source with Title: [XSS] you'll see a popup with the text "XSS" if you try any action (Delete, Change data template, Change Host, Enable...) - If you create a Graph with Title: [XSS] - If you create a Data Input Method with Name: [XSS] - If you create a Graph Template with Name: [XSS] - If you create a Host Templates with Name: [XSS]
Use CVE-2014-5026. If anyone has found that the patch fixes an additional attack vector (if that vector crosses privilege boundaries), then we could assign an additional CVE ID for the discovery by paulgevers. For example, there is not yet any report stating that the patch to user_admin.php resolves an issue that crosses privilege boundaries. - -- CVE assignment team, MITRE CVE Numbering Authority M/S M300 202 Burlington Road, Bedford, MA 01730 USA [ PGP key available through http://cve.mitre.org/cve/request_id.html ] -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.14 (SunOS) iQEcBAEBAgAGBQJTzsLfAAoJEKllVAevmvmshB0H/1eC2Rn9LHI+3uZfjv53VwyK JklpHD/yWvLQVZjIed9qrEUb3qjISnztp600LpqB6aesv+4qsDlwh6rHlpYLQuLj Z1tYowsE85auhZofCuM+2KsY3K+pYiN8/6E/w27WQEDozbd1sDO8ViWvLmEtrfAP waTfqbJqRVChd+9xxKM1/gxAmcRBQB3QS/6a+MZTwzzxiLSnkdIzzX0H9I8VEVQu chosLdj5VhOtMVkDfDx6a8eZeUSC4DFTkj0PG1RxgIny83CspuzuppjIAZ1RZFXP V52Mak1HZ137Nl9n3W669CDNtg/o9mVVqczoqcjTvm/VlK8ZqkI3x9cMfpYZVF4= =XUHr -----END PGP SIGNATURE-----
Current thread:
- CVE request: cacti XSS Moritz Muehlenhoff (Jul 20)
- Re: CVE request: cacti XSS cve-assign (Jul 22)