Show filters
152 Total Results
Displaying 71-80 of 152
Sort by:
Attacker Value
Unknown
CVE-2019-11025
Disclosure Date: April 08, 2019 (last updated November 27, 2024)
In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache, leading to XSS.
0
Attacker Value
Unknown
CVE-2018-20725
Disclosure Date: January 16, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability exists in graph_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Graph Vertical Label.
0
Attacker Value
Unknown
CVE-2018-20726
Disclosure Date: January 16, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname field for Devices.
0
Attacker Value
Unknown
CVE-2018-20723
Disclosure Date: January 16, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Name field for a Color.
0
Attacker Value
Unknown
CVE-2018-20724
Disclosure Date: January 16, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability exists in pollers.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname for Data Collectors.
0
Attacker Value
Unknown
CVE-2018-10060
Disclosure Date: April 12, 2018 (last updated November 26, 2024)
Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_uri function in lib/functions.php.
0
Attacker Value
Unknown
CVE-2018-10059
Disclosure Date: April 12, 2018 (last updated November 26, 2024)
Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER['PHP_SELF'] instead of $_SERVER['SCRIPT_NAME'] to determine a page name.
0
Attacker Value
Unknown
CVE-2018-10061
Disclosure Date: April 12, 2018 (last updated November 26, 2024)
Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used).
0
Attacker Value
Unknown
CVE-2016-10700
Disclosure Date: November 24, 2017 (last updated November 26, 2024)
auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database, because the guest user is not considered. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-2313.
0
Attacker Value
Unknown
CVE-2014-4000
Disclosure Date: November 15, 2017 (last updated November 26, 2024)
Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object, related to calling unserialize(stripslashes()).
0