Show filters
152 Total Results
Displaying 81-90 of 152
Sort by:
Attacker Value
Unknown

CVE-2017-16785

Disclosure Date: November 10, 2017 (last updated November 26, 2024)
Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.
0
Attacker Value
Unknown

CVE-2017-16661

Disclosure Date: November 08, 2017 (last updated November 26, 2024)
Cacti 1.1.27 allows remote authenticated administrators to read arbitrary files by placing the Log Path into a private directory, and then making a clog.php?filename= request, as demonstrated by filename=passwd (with a Log Path under /etc) to read /etc/passwd.
0
Attacker Value
Unknown

CVE-2017-16660

Disclosure Date: November 08, 2017 (last updated November 26, 2024)
Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path under the web root, and then making a remote_agent.php request containing PHP code in a Client-ip header.
0
Attacker Value
Unknown

CVE-2017-16641

Disclosure Date: November 07, 2017 (last updated November 26, 2024)
lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execute arbitrary OS commands via the path_rrdtool parameter in an action=save request to settings.php.
0
Attacker Value
Unknown

CVE-2017-15194

Disclosure Date: October 11, 2017 (last updated November 26, 2024)
include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2) the refresh page.
0
Attacker Value
Unknown

CVE-2017-12978

Disclosure Date: August 21, 2017 (last updated November 26, 2024)
lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.
0
Attacker Value
Unknown

CVE-2017-12927

Disclosure Date: August 18, 2017 (last updated November 26, 2024)
A cross-site scripting vulnerability exists in Cacti 1.1.17 in the method parameter in spikekill.php.
0
Attacker Value
Unknown

CVE-2017-12065

Disclosure Date: August 01, 2017 (last updated November 26, 2024)
spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter.
0
Attacker Value
Unknown

CVE-2017-12066

Disclosure Date: August 01, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti before 1.1.16 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable. NOTE: this vulnerability exists because of an incomplete fix (lack of the htmlspecialchars ENT_QUOTES flag) for CVE-2017-11163.
0
Attacker Value
Unknown

CVE-2017-11691

Disclosure Date: July 27, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in auth_profile.php in Cacti 1.1.13 allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.
0