Search CVE reports


Toggle filters

71 – 80 of 146 results


CVE-2019-16723

Medium priority
Vulnerable

In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_json.php request with a modified local_graph_id parameter.

1 affected package

cacti

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
cacti Not affected Not affected Not affected Vulnerable Not affected
Show less packages

CVE-2019-11025

Medium priority

Some fixes available 1 of 4

In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache, leading to XSS.

1 affected package

cacti

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
cacti Not affected Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2018-20726

Medium priority
Vulnerable

A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname field for Devices.

1 affected package

cacti

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
cacti Not affected Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2018-20725

Medium priority
Vulnerable

A cross-site scripting (XSS) vulnerability exists in graph_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Graph Vertical Label.

1 affected package

cacti

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
cacti Not affected Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2018-20724

Medium priority
Vulnerable

A cross-site scripting (XSS) vulnerability exists in pollers.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname for Data Collectors.

1 affected package

cacti

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
cacti Not affected Not affected Not affected Vulnerable Not affected
Show less packages

CVE-2018-20723

Medium priority
Vulnerable

A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Name field for a Color.

1 affected package

cacti

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
cacti Not affected Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2013-7464

Medium priority
Not affected

In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not configured, the Anti-CSRF Token used is predictable and would permit an attacker to bypass the CSRF protections, because an automatically generated secret is not used.

1 affected package

cacti

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
cacti Not affected Not affected
Show less packages

CVE-2018-10061

Medium priority
Vulnerable

Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used).

1 affected package

cacti

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
cacti Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-10060

Medium priority
Vulnerable

Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_uri function in lib/functions.php.

1 affected package

cacti

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
cacti Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-10059

Medium priority
Ignored

Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER['PHP_SELF'] instead of $_SERVER['SCRIPT_NAME'] to determine a page name.

1 affected package

cacti

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
cacti Not affected Not affected
Show less packages