Cross-site scripting in Debian products - CVE-2014-2326
Published: March 27, 2014 / Updated: August 10, 2020
SUSE
The Cacti Group, Inc.
Debian
Fedora
Opensuse
Debian Linux
Cacti
Detailed vulnerability description
Vulnerability allows a remote attacker to perform XSS attacks.
The vulnerability is caused by an input validation error in cdef.php in Cacti 0.8.7g, 0.8.8b, and earlier. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in victim's browser in security context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
How to mitigate CVE-2014-2326
Sources
- http://bugs.cacti.net/view.php?id=2431
- http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131821.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131842.html
- http://lists.opensuse.org/opensuse-updates/2015-03/msg00034.html
- http://packetstormsecurity.com/files/125849/Deutsche-Telekom-CERT-Advisory-DTC-A-20140324-001.html
- http://secunia.com/advisories/57647
- http://secunia.com/advisories/59203
- http://svn.cacti.net/viewvc?view=rev&revision=7443
- http://www.debian.org/security/2014/dsa-2970
- http://www.securityfocus.com/archive/1/531588
- http://www.securityfocus.com/bid/66390
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742768
- https://security.gentoo.org/glsa/201509-03