CVE-2017-12927
- EPSS 0.52%
- Veröffentlicht 18.08.2017 02:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
A cross-site scripting vulnerability exists in Cacti 1.1.17 in the method parameter in spikekill.php.
CVE-2017-12065
- EPSS 3.32%
- Veröffentlicht 01.08.2017 05:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter.
CVE-2017-12066
- EPSS 0.24%
- Veröffentlicht 01.08.2017 05:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti before 1.1.16 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable. NOTE: th...
CVE-2017-11691
- EPSS 0.51%
- Veröffentlicht 27.07.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in auth_profile.php in Cacti 1.1.13 allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.
CVE-2017-1000031
- EPSS 1.09%
- Veröffentlicht 17.07.2017 13:18:16
- Zuletzt bearbeitet 20.04.2025 01:37:25
SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary SQL commands via the graph_template_input_id and graph_template_id parameters.
CVE-2017-1000032
- EPSS 0.2%
- Veröffentlicht 17.07.2017 13:18:16
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter to tree.php and drp_action parameter to data_sources.php.
CVE-2017-11163
- EPSS 0.22%
- Veröffentlicht 10.07.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable.
CVE-2017-10970
- EPSS 0.22%
- Veröffentlicht 06.07.2017 11:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remote anonymous users to inject arbitrary web script or HTML via the id parameter, related to the die_html_input_error function in lib/html_validate.php.
CVE-2016-2313
- EPSS 1.08%
- Veröffentlicht 13.04.2016 17:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
CVE-2016-3172
- EPSS 0.5%
- Veröffentlicht 12.04.2016 16:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in tree.php in Cacti 0.8.8g and earlier allows remote authenticated users to execute arbitrary SQL commands via the parent_id parameter in an item_edit action.