CVE-2020-7106
- EPSS 4.09%
- Veröffentlicht 16.01.2020 04:15:11
- Zuletzt bearbeitet 21.11.2024 05:36:38
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string fr...
CVE-2020-7058
- EPSS 0.77%
- Veröffentlicht 15.01.2020 07:15:12
- Zuletzt bearbeitet 21.11.2024 05:36:35
data_input.php in Cacti 1.2.8 allows remote code execution via a crafted Input String to Data Collection -> Data Input Methods -> Unix -> Ping Host. NOTE: the vendor has stated "This is a false alarm.
CVE-2019-17358
- EPSS 2.42%
- Veröffentlicht 12.12.2019 14:15:16
- Zuletzt bearbeitet 21.11.2024 04:32:10
Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions taken by Cacti ...
CVE-2019-16723
- EPSS 0.27%
- Veröffentlicht 23.09.2019 15:15:10
- Zuletzt bearbeitet 21.11.2024 04:31:03
In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_json.php request with a modified local_graph_id parameter.
CVE-2019-11025
- EPSS 0.67%
- Veröffentlicht 08.04.2019 23:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:23
In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache, leading to XSS.
CVE-2018-20723
- EPSS 0.5%
- Veröffentlicht 16.01.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:02:02
A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Name field for a Color.
CVE-2018-20724
- EPSS 0.58%
- Veröffentlicht 16.01.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:02:02
A cross-site scripting (XSS) vulnerability exists in pollers.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname for Data Collectors.
CVE-2018-20725
- EPSS 0.5%
- Veröffentlicht 16.01.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:02:02
A cross-site scripting (XSS) vulnerability exists in graph_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Graph Vertical Label.
CVE-2018-20726
- EPSS 0.51%
- Veröffentlicht 16.01.2019 16:29:00
- Zuletzt bearbeitet 21.11.2024 04:02:02
A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname field for Devices.
CVE-2018-10059
- EPSS 0.29%
- Veröffentlicht 12.04.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:44
Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER['PHP_SELF'] instead of $_SERVER['SCRIPT_NAME'] to determine a page name.