Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2021-26247

Disclosure Date: January 19, 2022 (last updated February 23, 2025)
As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully execute the JavaScript payload present in the "ref" URL parameter.
Attacker Value
Unknown

CVE-2014-5262

Disclosure Date: August 22, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-5261

Disclosure Date: August 22, 2014 (last updated October 05, 2023)
The graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a font size, related to the rrdtool commandline in lib/rrd.php.
0
Attacker Value
Unknown

CVE-2014-2326

Disclosure Date: March 27, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in cdef.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-5589

Disclosure Date: August 29, 2013 (last updated October 05, 2023)
SQL injection vulnerability in cacti/host.php in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2013-5588

Disclosure Date: August 29, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the step parameter to install/index.php or (2) the id parameter to cacti/host.php.
0
Attacker Value
Unknown

CVE-2013-1434

Disclosure Date: August 23, 2013 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in (1) api_poller.php and (2) utility.php in Cacti before 0.8.8b allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-1435

Disclosure Date: August 23, 2013 (last updated October 05, 2023)
(1) snmp.php and (2) rrd.php in Cacti before 0.8.8b allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.
0
Attacker Value
Unknown

CVE-2011-5223

Disclosure Date: October 25, 2012 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in logout.php in Cacti before 0.8.7i allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
0