CVE-2014-4000
- EPSS 1.1%
- Veröffentlicht 15.11.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object, related to calling unserialize(stripslashes()).
CVE-2017-16785
- EPSS 0.2%
- Veröffentlicht 10.11.2017 23:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.
- EPSS 1.46%
- Veröffentlicht 08.11.2017 05:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path under the web root, and then making a remote_agent.php request containing PHP code in a Client-ip header.
CVE-2017-16661
- EPSS 0.18%
- Veröffentlicht 08.11.2017 05:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cacti 1.1.27 allows remote authenticated administrators to read arbitrary files by placing the Log Path into a private directory, and then making a clog.php?filename= request, as demonstrated by filename=passwd (with a Log Path under /etc) to read /e...
- EPSS 0.47%
- Veröffentlicht 07.11.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execute arbitrary OS commands via the path_rrdtool parameter in an action=save request to settings.php.
CVE-2017-15194
- EPSS 0.31%
- Veröffentlicht 11.10.2017 01:32:54
- Zuletzt bearbeitet 20.04.2025 01:37:25
include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2) the refresh page.
CVE-2017-12978
- EPSS 0.3%
- Veröffentlicht 21.08.2017 07:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.
CVE-2017-12927
- EPSS 0.52%
- Veröffentlicht 18.08.2017 02:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
A cross-site scripting vulnerability exists in Cacti 1.1.17 in the method parameter in spikekill.php.
CVE-2017-12065
- EPSS 3.32%
- Veröffentlicht 01.08.2017 05:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter.
CVE-2017-12066
- EPSS 0.24%
- Veröffentlicht 01.08.2017 05:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti before 1.1.16 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable. NOTE: th...