Cacti

Cacti

137 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 47.48%
  • Veröffentlicht 07.10.2024 21:15:15
  • Zuletzt bearbeitet 17.10.2024 17:58:55

Cacti is an open source performance and fault management framework. An admin user can create a device with a malicious hostname containing php code and repeat the installation process (completing only step 5 of the installation process is enough, no ...

Exploit
  • EPSS 0.79%
  • Veröffentlicht 14.05.2024 15:38:39
  • Zuletzt bearbeitet 18.12.2024 20:44:22

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set their password. `compat_password_hash` use `password_hash` if there is it, else use `md5`. When verify...

Exploit
  • EPSS 3.63%
  • Veröffentlicht 14.05.2024 15:25:26
  • Zuletzt bearbeitet 18.12.2024 20:49:57

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, there is a file inclusion issue in the `lib/plugin.php` file. Combined with SQL injection vulnerabilities, remote code execution can be implemented. The...

Exploit
  • EPSS 1.08%
  • Veröffentlicht 14.05.2024 15:25:26
  • Zuletzt bearbeitet 18.12.2024 20:38:39

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the SQL statement in `create_all_header_node...

Exploit
  • EPSS 3.56%
  • Veröffentlicht 14.05.2024 15:25:25
  • Zuletzt bearbeitet 18.12.2024 20:47:06

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `form_save()` function in `graph_template_inputs.php` is not thoroughly checked and is used to concatenate the SQL statement ...

Exploit
  • EPSS 42.3%
  • Veröffentlicht 14.05.2024 15:25:21
  • Zuletzt bearbeitet 18.12.2024 18:29:21

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, a SQL injection vulnerability in `automation_get_new_graphs_sql` function of `api_automation.php` allows authenticated users to exploit these SQL inject...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 14.05.2024 15:25:20
  • Zuletzt bearbeitet 18.12.2024 18:28:19

Cacti provides an operational monitoring and fault management framework. Prior to 1.2.27, some of the data stored in `form_save()` function in `data_queries.php` is not thoroughly checked and is used to concatenate the HTML statement in `grow_right_p...

Exploit
  • EPSS 5.42%
  • Veröffentlicht 14.05.2024 15:25:20
  • Zuletzt bearbeitet 18.12.2024 18:28:58

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules_form_save()` function in `automation_tree_rules.php` is not thoroughly checked and is used to concaten...

  • EPSS 0.2%
  • Veröffentlicht 14.05.2024 15:22:18
  • Zuletzt bearbeitet 21.11.2024 09:11:35

Cacti provides an operational monitoring and fault management framework. A reflected cross-site scripting vulnerability on the 1.3.x DEV branch allows attackers to obtain cookies of administrator and other users and fake their login using obtained co...

  • EPSS 93.14%
  • Veröffentlicht 14.05.2024 15:17:15
  • Zuletzt bearbeitet 21.11.2024 09:08:34

Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x DEV branch allows any unauthenticated user to execute arbitrary command on the server when `register_argc_argv` option of PHP is `...