Vulnerability Name:

CVE-2009-4032 (CCN-54388)

Assigned:2009-11-22
Published:2009-11-22
Updated:2023-02-13
Summary:
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.9 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:TF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:TF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Consequences:Gain Access
References:Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: MITRE
Type: CNA
CVE-2009-4032

Source: CCN
Type: Cacti Web Site
Cross-Site Scripting Fixes

Source: secalert@redhat.com
Type: Patch
secalert@redhat.com

Source: CCN
Type: JVN#09758120
Cacti vulnerable to cross-site scripting

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: SA37481
Cacti Multiple Vulnerabilities

Source: CCN
Type: SA41041
Red Hat High Performance Computing (HPC) Solution Multiple Vulnerabilities

Source: secalert@redhat.com
Type: Patch
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: DEBIAN
Type: DSA-1954
cacti -- insufficient input sanitising

Source: secalert@redhat.com
Type: Patch
secalert@redhat.com

Source: secalert@redhat.com
Type: Patch
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: OSVDB ID: 60483
Cacti lib/timespan_settings.php Multiple Parameter XSS

Source: CCN
Type: OSVDB ID: 60564
Cacti lib/html_form.php Multiple Parameter XSS

Source: CCN
Type: OSVDB ID: 60565
Cacti include/top_graph_header.php Multiple Parameter XSS

Source: CCN
Type: OSVDB ID: 60566
Cacti graph.php Multiple Parameter XSS

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: BID-37109
Cacti Multiple Cross Site Scripting and HTML Injection Vulnerabilities

Source: secalert@redhat.com
Type: Patch
secalert@redhat.com

Source: CCN
Type: BID-42575
Cacti Cross Site Scripting and HTML Injection Vulnerabilities

Source: secalert@redhat.com
Type: Patch, Vendor Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: XF
Type: UNKNOWN
cacti-name-xss(54388)

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: SUSE
Type: SUSE-SR:2009:020
SUSE Security Summary Report

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/a:cacti:cacti:0.8.7e:*:*:*:*:*:*:*
  • AND
  • cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0::x86_64:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:5.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandriva:enterprise_server:5:*:*:*:*:*:*:*
  • OR cpe:/o:mandriva:enterprise_server:5:*:*:*:x86_64:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20094032
    V
    CVE-2009-4032
    2015-11-16
    oval:org.mitre.oval:def:6983
    P
    DSA-1954 cacti -- insufficient input sanitising
    2014-06-23
    oval:org.mitre.oval:def:13514
    P
    DSA-1954-1 cacti -- insufficient input sanitising
    2014-06-23
    oval:org.debian:def:1954
    V
    insufficient input sanitising
    2009-12-16
    BACK
    cacti cacti 0.8.7e
    mandrakesoft mandrake linux corporate server 4.0
    mandrakesoft mandrake linux corporate server 4.0
    debian debian linux 4.0
    debian debian linux 5.0
    mandriva enterprise server 5
    mandriva enterprise server 5