Filtered by vendor Cacti
Subscriptions
Filtered by product Cacti
Subscriptions
Total
130 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2017-10970 | 1 Cacti | 1 Cacti | 2025-04-20 | N/A |
Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remote anonymous users to inject arbitrary web script or HTML via the id parameter, related to the die_html_input_error function in lib/html_validate.php. | ||||
CVE-2017-12065 | 1 Cacti | 1 Cacti | 2025-04-20 | N/A |
spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter. | ||||
CVE-2017-12978 | 1 Cacti | 1 Cacti | 2025-04-20 | N/A |
lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user. | ||||
CVE-2017-11163 | 1 Cacti | 1 Cacti | 2025-04-20 | N/A |
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable. | ||||
CVE-2017-16785 | 1 Cacti | 1 Cacti | 2025-04-20 | N/A |
Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php. | ||||
CVE-2017-11691 | 1 Cacti | 1 Cacti | 2025-04-20 | N/A |
Cross-site scripting (XSS) vulnerability in auth_profile.php in Cacti 1.1.13 allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers. | ||||
CVE-2017-15194 | 1 Cacti | 1 Cacti | 2025-04-20 | N/A |
include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2) the refresh page. | ||||
CVE-2017-12927 | 1 Cacti | 1 Cacti | 2025-04-20 | N/A |
A cross-site scripting vulnerability exists in Cacti 1.1.17 in the method parameter in spikekill.php. | ||||
CVE-2017-12066 | 1 Cacti | 1 Cacti | 2025-04-20 | N/A |
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti before 1.1.16 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable. NOTE: this vulnerability exists because of an incomplete fix (lack of the htmlspecialchars ENT_QUOTES flag) for CVE-2017-11163. | ||||
CVE-2016-10700 | 1 Cacti | 1 Cacti | 2025-04-20 | N/A |
auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database, because the guest user is not considered. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-2313. | ||||
CVE-2017-16660 | 1 Cacti | 1 Cacti | 2025-04-20 | N/A |
Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path under the web root, and then making a remote_agent.php request containing PHP code in a Client-ip header. | ||||
CVE-2017-16661 | 1 Cacti | 1 Cacti | 2025-04-20 | N/A |
Cacti 1.1.27 allows remote authenticated administrators to read arbitrary files by placing the Log Path into a private directory, and then making a clog.php?filename= request, as demonstrated by filename=passwd (with a Log Path under /etc) to read /etc/passwd. | ||||
CVE-2017-1000031 | 1 Cacti | 1 Cacti | 2025-04-20 | N/A |
SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary SQL commands via the graph_template_input_id and graph_template_id parameters. | ||||
CVE-2017-1000032 | 1 Cacti | 1 Cacti | 2025-04-20 | N/A |
Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter to tree.php and drp_action parameter to data_sources.php. | ||||
CVE-2014-4000 | 1 Cacti | 1 Cacti | 2025-04-20 | N/A |
Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object, related to calling unserialize(stripslashes()). | ||||
CVE-2017-16641 | 1 Cacti | 1 Cacti | 2025-04-20 | N/A |
lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execute arbitrary OS commands via the path_rrdtool parameter in an action=save request to settings.php. | ||||
CVE-2025-24367 | 1 Cacti | 1 Cacti | 2025-04-18 | 8.8 High |
Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29. | ||||
CVE-2025-24368 | 1 Cacti | 1 Cacti | 2025-04-18 | 7.5 High |
Cacti is an open source performance and fault management framework. Some of the data stored in automation_tree_rules.php is not thoroughly checked and is used to concatenate the SQL statement in build_rule_item_filter() function from lib/api_automation.php, resulting in SQL injection. This vulnerability is fixed in 1.2.29. | ||||
CVE-2015-4634 | 1 Cacti | 1 Cacti | 2025-04-12 | N/A |
SQL injection vulnerability in graphs.php in Cacti before 0.8.8e allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter. | ||||
CVE-2014-5025 | 3 Cacti, Debian, Opensuse | 3 Cacti, Debian Linux, Opensuse | 2025-04-12 | N/A |
Cross-site scripting (XSS) vulnerability in data_sources.php in Cacti 0.8.8b allows remote authenticated users with console access to inject arbitrary web script or HTML via the name_cache parameter in a ds_edit action. |