Cacti

Cacti

137 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.33%
  • Published 15.12.2015 21:59:10
  • Last modified 12.04.2025 10:46:40

SQL injection vulnerability in the host_new_graphs_save function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted serialized data in the selected_graphs_array parameter in a...

Exploit
  • EPSS 0.41%
  • Published 11.08.2015 14:59:10
  • Last modified 12.04.2025 10:46:40

SQL injection vulnerability in graphs.php in Cacti before 0.8.8e allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter.

  • EPSS 0.32%
  • Published 10.07.2015 15:59:00
  • Last modified 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in settings.php in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • EPSS 0.64%
  • Published 17.06.2015 18:59:09
  • Last modified 12.04.2025 10:46:40

SQL injection vulnerability in the get_hash_graph_template function in lib/functions.php in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via the graph_template_id parameter to graph_templates.php.

  • EPSS 3.76%
  • Published 17.06.2015 18:59:07
  • Last modified 12.04.2025 10:46:40

SQL injection vulnerability in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving a cdef id.

  • EPSS 0.43%
  • Published 17.06.2015 18:59:01
  • Last modified 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • EPSS 0.35%
  • Published 22.05.2015 00:59:02
  • Last modified 12.04.2025 10:46:40

SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote authenticated users to execute arbitrary SQL commands via the local_graph_id parameter, a different vulnerability than CVE-2007-6035.

Exploit
  • EPSS 0.45%
  • Published 20.10.2014 17:55:06
  • Last modified 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in data_sources.php in Cacti 0.8.8b allows remote authenticated users with console access to inject arbitrary web script or HTML via the name_cache parameter in a ds_edit action.

Exploit
  • EPSS 0.35%
  • Published 20.10.2014 17:55:06
  • Last modified 12.04.2025 10:46:40

Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote authenticated users with console access to inject arbitrary web script or HTML via a (1) Graph Tree Title in a delete or (2) edit action; (3) CDEF Name, (4) Data Input M...

  • EPSS 1.34%
  • Published 22.08.2014 14:55:09
  • Last modified 12.04.2025 10:46:40

The graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a font size, related to the rrdtool commandline in lib/rrd.php.