CVE-2017-11691
- EPSS 0.51%
- Veröffentlicht 27.07.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in auth_profile.php in Cacti 1.1.13 allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.
CVE-2017-1000031
- EPSS 1.09%
- Veröffentlicht 17.07.2017 13:18:16
- Zuletzt bearbeitet 20.04.2025 01:37:25
SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary SQL commands via the graph_template_input_id and graph_template_id parameters.
CVE-2017-1000032
- EPSS 0.2%
- Veröffentlicht 17.07.2017 13:18:16
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter to tree.php and drp_action parameter to data_sources.php.
CVE-2017-11163
- EPSS 0.22%
- Veröffentlicht 10.07.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable.
CVE-2017-10970
- EPSS 0.22%
- Veröffentlicht 06.07.2017 11:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remote anonymous users to inject arbitrary web script or HTML via the id parameter, related to the die_html_input_error function in lib/html_validate.php.
CVE-2016-2313
- EPSS 1.08%
- Veröffentlicht 13.04.2016 17:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
CVE-2016-3172
- EPSS 0.52%
- Veröffentlicht 12.04.2016 16:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in tree.php in Cacti 0.8.8g and earlier allows remote authenticated users to execute arbitrary SQL commands via the parent_id parameter in an item_edit action.
CVE-2015-8604
- EPSS 0.63%
- Veröffentlicht 11.04.2016 21:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in the host_new_graphs function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via the cg_g parameter in a save action.
CVE-2016-3659
- EPSS 0.59%
- Veröffentlicht 11.04.2016 15:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote authenticated users to execute arbitrary SQL commands via the host_group_data parameter.
CVE-2015-8369
- EPSS 0.5%
- Veröffentlicht 17.12.2015 19:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in include/top_graph_header.php in Cacti 0.8.8f and earlier allows remote attackers to execute arbitrary SQL commands via the rra_id parameter in a properties action to graph.php.