Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parentid parameter to tree.php and drpaction parameter to data_sources.php.
{ "binaries": [ { "binary_name": "cacti", "binary_version": "0.8.8b+dfsg-5ubuntu0.1" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "cacti", "binary_version": "0.8.8f+ds1-4ubuntu4.16.04.2" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "cacti", "binary_version": "1.1.38+ds1-1" } ], "availability": "No subscription required" }