Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-Id: <201407222007.s6MK7n5O028490@linus.mitre.org>
Date: Tue, 22 Jul 2014 16:07:49 -0400 (EDT)
From: cve-assign@...re.org
To: jmm@...ian.org
Cc: cve-assign@...re.org, oss-security@...ts.openwall.com
Subject: Re: CVE request: cacti XSS

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> http://bugs.cacti.net/view.php?id=2456

> Product Version 0.8.8b

> You need console access to create any of these items, but you don't
> need full administrator privileges.

(One of the vectors reported by flekyy was separately disclosed a week
before the others reported by flekyy.)


> Add a new Data Source with the following name: [XSS] -- Browse to
> http://<IP>/cacti/data_sources.php [^] and you'll see a popup with the
> text "XSS"

Use CVE-2014-5025.


>  - If you create a Graph Tree with Title: [XSS]
> 
>  - If you create a CDEF with Name: [XSS]
> 
>  - If you create a Data Source with Title: [XSS] you'll see a popup
>    with the text "XSS" if you try any action (Delete, Change data
>    template, Change Host, Enable...)
> 
>  - If you create a Graph with Title: [XSS]
> 
>  - If you create a Data Input Method with Name: [XSS]
> 
>  - If you create a Graph Template with Name: [XSS]
> 
>  - If you create a Host Templates with Name: [XSS]

Use CVE-2014-5026.


If anyone has found that the patch fixes an additional attack vector
(if that vector crosses privilege boundaries), then we could assign an
additional CVE ID for the discovery by paulgevers. For example, there
is not yet any report stating that the patch to user_admin.php
resolves an issue that crosses privilege boundaries.

- -- 
CVE assignment team, MITRE CVE Numbering Authority
M/S M300
202 Burlington Road, Bedford, MA 01730 USA
[ PGP key available through http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (SunOS)

iQEcBAEBAgAGBQJTzsLfAAoJEKllVAevmvmshB0H/1eC2Rn9LHI+3uZfjv53VwyK
JklpHD/yWvLQVZjIed9qrEUb3qjISnztp600LpqB6aesv+4qsDlwh6rHlpYLQuLj
Z1tYowsE85auhZofCuM+2KsY3K+pYiN8/6E/w27WQEDozbd1sDO8ViWvLmEtrfAP
waTfqbJqRVChd+9xxKM1/gxAmcRBQB3QS/6a+MZTwzzxiLSnkdIzzX0H9I8VEVQu
chosLdj5VhOtMVkDfDx6a8eZeUSC4DFTkj0PG1RxgIny83CspuzuppjIAZ1RZFXP
V52Mak1HZ137Nl9n3W669CDNtg/o9mVVqczoqcjTvm/VlK8ZqkI3x9cMfpYZVF4=
=XUHr
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.