CVE-2015-8377
- EPSS 0.33%
- Veröffentlicht 15.12.2015 21:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in the host_new_graphs_save function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted serialized data in the selected_graphs_array parameter in a...
CVE-2015-4634
- EPSS 0.41%
- Veröffentlicht 11.08.2015 14:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in graphs.php in Cacti before 0.8.8e allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter.
CVE-2015-2967
- EPSS 0.32%
- Veröffentlicht 10.07.2015 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in settings.php in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2015-4454
- EPSS 0.64%
- Veröffentlicht 17.06.2015 18:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in the get_hash_graph_template function in lib/functions.php in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via the graph_template_id parameter to graph_templates.php.
CVE-2015-4342
- EPSS 3.76%
- Veröffentlicht 17.06.2015 18:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving a cdef id.
CVE-2015-2665
- EPSS 0.43%
- Veröffentlicht 17.06.2015 18:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2015-0916
- EPSS 0.35%
- Veröffentlicht 22.05.2015 00:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote authenticated users to execute arbitrary SQL commands via the local_graph_id parameter, a different vulnerability than CVE-2007-6035.
CVE-2014-5025
- EPSS 0.45%
- Veröffentlicht 20.10.2014 17:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in data_sources.php in Cacti 0.8.8b allows remote authenticated users with console access to inject arbitrary web script or HTML via the name_cache parameter in a ds_edit action.
CVE-2014-5026
- EPSS 0.35%
- Veröffentlicht 20.10.2014 17:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote authenticated users with console access to inject arbitrary web script or HTML via a (1) Graph Tree Title in a delete or (2) edit action; (3) CDEF Name, (4) Data Input M...
CVE-2014-5261
- EPSS 1.34%
- Veröffentlicht 22.08.2014 14:55:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a font size, related to the rrdtool commandline in lib/rrd.php.