Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the (1) drpaction parameter to cdef.php, (2) datainput.php, (3) dataqueries.php, (4) datasources.php, (5) datatemplates.php, (6) graphtemplates.php, (7) graphs.php, (8) host.php, or (9) hosttemplates.php or the (10) graphtemplateinputid or (11) graphtemplateid parameter to graphtemplatesinputs.php.