Show filters
152 Total Results
Displaying 51-60 of 152
Sort by:
Attacker Value
Unknown
CVE-2022-48538
Disclosure Date: August 22, 2023 (last updated October 08, 2023)
In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() allows a zero as the password.
0
Attacker Value
Unknown
CVE-2022-41444
Disclosure Date: August 22, 2023 (last updated October 08, 2023)
Cross Site Scripting (XSS) vulnerability in Cacti 1.2.21 via crafted POST request to graphs_new.php.
0
Attacker Value
Unknown
CVE-2023-37543
Disclosure Date: August 10, 2023 (last updated October 08, 2023)
Cacti before 1.2.6 allows IDOR (Insecure Direct Object Reference) for accessing any graph via a modified local_graph_id parameter to graph_xport.php. This is a different vulnerability than CVE-2019-16723.
0
Attacker Value
Unknown
CVE-2022-0730
Disclosure Date: March 03, 2022 (last updated February 23, 2025)
Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.
0
Attacker Value
Unknown
CVE-2021-3816
Disclosure Date: January 19, 2022 (last updated February 23, 2025)
Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix field during the creation of a new group via "Copy" method at user_group_admin.php.
0
Attacker Value
Unknown
CVE-2021-26247
Disclosure Date: January 19, 2022 (last updated February 23, 2025)
As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully execute the JavaScript payload present in the "ref" URL parameter.
0
Attacker Value
Unknown
CVE-2021-23225
Disclosure Date: January 19, 2022 (last updated February 23, 2025)
Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "new_username" field during creation of a new user via "Copy" method at user_admin.php.
0
Attacker Value
Unknown
CVE-2020-14424
Disclosure Date: November 14, 2021 (last updated February 23, 2025)
Cacti before 1.2.18 allows remote attackers to trigger XSS via template import for the midwinter theme.
0
Attacker Value
Unknown
CVE-2020-23226
Disclosure Date: August 27, 2021 (last updated February 23, 2025)
Multiple Cross Site Scripting (XSS) vulneratiblities exist in Cacti 1.2.12 in (1) reports_admin.php, (2) data_queries.php, (3) data_input.php, (4) graph_templates.php, (5) graphs.php, (6) reports_admin.php, and (7) data_input.php.
0
Attacker Value
Unknown
CVE-2020-35701
Disclosure Date: January 11, 2021 (last updated February 22, 2025)
An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in data_debug.php allows remote authenticated attackers to execute arbitrary SQL commands via the site_id parameter. This can lead to remote code execution.
0