rpm package
opensuse/cacti&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/cacti&distro=openSUSE%20Tumbleweed
Vulnerabilities (87)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2017-12978 | Med | 5.4 | < 1.2.18-1.2 | 1.2.18-1.2 | Aug 21, 2017 | lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user. | |
| CVE-2017-12927 | Med | 6.1 | < 1.2.18-1.2 | 1.2.18-1.2 | Aug 18, 2017 | A cross-site scripting vulnerability exists in Cacti 1.1.17 in the method parameter in spikekill.php. | |
| CVE-2017-12065 | Cri | 9.8 | < 1.2.18-1.2 | 1.2.18-1.2 | Aug 1, 2017 | spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter. | |
| CVE-2017-11691 | Med | 5.4 | < 1.2.18-1.2 | 1.2.18-1.2 | Jul 27, 2017 | Cross-site scripting (XSS) vulnerability in auth_profile.php in Cacti 1.1.13 allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers. | |
| CVE-2017-11163 | Med | 5.4 | < 1.2.18-1.2 | 1.2.18-1.2 | Jul 10, 2017 | Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable. | |
| CVE-2017-10970 | Med | 5.4 | < 1.2.18-1.2 | 1.2.18-1.2 | Jul 6, 2017 | Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remote anonymous users to inject arbitrary web script or HTML via the id parameter, related to the die_html_input_error function in lib/html_validate.php. | |
| CVE-2016-2313 | Hig | 8.8 | < 0.8.8h-1.2 | 0.8.8h-1.2 | Apr 13, 2016 | auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database. | |
| CVE-2016-3172 | Hig | 8.8 | < 0.8.8h-1.2 | 0.8.8h-1.2 | Apr 12, 2016 | SQL injection vulnerability in tree.php in Cacti 0.8.8g and earlier allows remote authenticated users to execute arbitrary SQL commands via the parent_id parameter in an item_edit action. | |
| CVE-2015-8604 | Hig | 8.8 | < 0.8.8h-1.2 | 0.8.8h-1.2 | Apr 11, 2016 | SQL injection vulnerability in the host_new_graphs function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via the cg_g parameter in a save action. | |
| CVE-2016-3659 | Hig | 8.8 | < 0.8.8h-1.2 | 0.8.8h-1.2 | Apr 11, 2016 | SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote authenticated users to execute arbitrary SQL commands via the host_group_data parameter. | |
| CVE-2015-8369 | — | < 0.8.8h-1.2 | 0.8.8h-1.2 | Dec 17, 2015 | SQL injection vulnerability in include/top_graph_header.php in Cacti 0.8.8f and earlier allows remote attackers to execute arbitrary SQL commands via the rra_id parameter in a properties action to graph.php. | ||
| CVE-2015-8377 | — | < 0.8.8h-1.2 | 0.8.8h-1.2 | Dec 15, 2015 | SQL injection vulnerability in the host_new_graphs_save function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted serialized data in the selected_graphs_array parameter in a save action. | ||
| CVE-2015-4634 | — | < 0.8.8h-1.2 | 0.8.8h-1.2 | Aug 11, 2015 | SQL injection vulnerability in graphs.php in Cacti before 0.8.8e allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter. | ||
| CVE-2015-4342 | — | < 0.8.8h-1.2 | 0.8.8h-1.2 | Jun 17, 2015 | SQL injection vulnerability in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving a cdef id. | ||
| CVE-2014-5026 | — | < 0.8.8h-1.2 | 0.8.8h-1.2 | Oct 20, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote authenticated users with console access to inject arbitrary web script or HTML via a (1) Graph Tree Title in a delete or (2) edit action; (3) CDEF Name, (4) Data Input Method Name, or (5) Host Templa | ||
| CVE-2014-5025 | — | < 0.8.8h-1.2 | 0.8.8h-1.2 | Oct 20, 2014 | Cross-site scripting (XSS) vulnerability in data_sources.php in Cacti 0.8.8b allows remote authenticated users with console access to inject arbitrary web script or HTML via the name_cache parameter in a ds_edit action. | ||
| CVE-2014-4002 | — | < 0.8.8h-1.2 | 0.8.8h-1.2 | Jul 3, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the (1) drp_action parameter to cdef.php, (2) data_input.php, (3) data_queries.php, (4) data_sources.php, (5) data_templates.php, (6) graph_templa | ||
| CVE-2014-2709 | — | < 0.8.8h-1.2 | 0.8.8h-1.2 | Apr 23, 2014 | lib/rrd.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified parameters. | ||
| CVE-2014-2328 | — | < 0.8.8h-1.2 | 0.8.8h-1.2 | Apr 23, 2014 | lib/graph_export.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in unspecified vectors. | ||
| CVE-2014-2327 | — | < 0.8.8h-1.2 | 0.8.8h-1.2 | Apr 23, 2014 | Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users for unspecified commands, as demonstrated by requests that (1) modify binary files, (2) modify configurations, or (3) add arbitrary u |
- affected < 1.2.18-1.2fixed 1.2.18-1.2
lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.
- affected < 1.2.18-1.2fixed 1.2.18-1.2
A cross-site scripting vulnerability exists in Cacti 1.1.17 in the method parameter in spikekill.php.
- affected < 1.2.18-1.2fixed 1.2.18-1.2
spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter.
- affected < 1.2.18-1.2fixed 1.2.18-1.2
Cross-site scripting (XSS) vulnerability in auth_profile.php in Cacti 1.1.13 allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.
- affected < 1.2.18-1.2fixed 1.2.18-1.2
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable.
- affected < 1.2.18-1.2fixed 1.2.18-1.2
Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remote anonymous users to inject arbitrary web script or HTML via the id parameter, related to the die_html_input_error function in lib/html_validate.php.
- affected < 0.8.8h-1.2fixed 0.8.8h-1.2
auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
- affected < 0.8.8h-1.2fixed 0.8.8h-1.2
SQL injection vulnerability in tree.php in Cacti 0.8.8g and earlier allows remote authenticated users to execute arbitrary SQL commands via the parent_id parameter in an item_edit action.
- affected < 0.8.8h-1.2fixed 0.8.8h-1.2
SQL injection vulnerability in the host_new_graphs function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via the cg_g parameter in a save action.
- affected < 0.8.8h-1.2fixed 0.8.8h-1.2
SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote authenticated users to execute arbitrary SQL commands via the host_group_data parameter.
- CVE-2015-8369Dec 17, 2015affected < 0.8.8h-1.2fixed 0.8.8h-1.2
SQL injection vulnerability in include/top_graph_header.php in Cacti 0.8.8f and earlier allows remote attackers to execute arbitrary SQL commands via the rra_id parameter in a properties action to graph.php.
- CVE-2015-8377Dec 15, 2015affected < 0.8.8h-1.2fixed 0.8.8h-1.2
SQL injection vulnerability in the host_new_graphs_save function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted serialized data in the selected_graphs_array parameter in a save action.
- CVE-2015-4634Aug 11, 2015affected < 0.8.8h-1.2fixed 0.8.8h-1.2
SQL injection vulnerability in graphs.php in Cacti before 0.8.8e allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter.
- CVE-2015-4342Jun 17, 2015affected < 0.8.8h-1.2fixed 0.8.8h-1.2
SQL injection vulnerability in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving a cdef id.
- CVE-2014-5026Oct 20, 2014affected < 0.8.8h-1.2fixed 0.8.8h-1.2
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote authenticated users with console access to inject arbitrary web script or HTML via a (1) Graph Tree Title in a delete or (2) edit action; (3) CDEF Name, (4) Data Input Method Name, or (5) Host Templa
- CVE-2014-5025Oct 20, 2014affected < 0.8.8h-1.2fixed 0.8.8h-1.2
Cross-site scripting (XSS) vulnerability in data_sources.php in Cacti 0.8.8b allows remote authenticated users with console access to inject arbitrary web script or HTML via the name_cache parameter in a ds_edit action.
- CVE-2014-4002Jul 3, 2014affected < 0.8.8h-1.2fixed 0.8.8h-1.2
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the (1) drp_action parameter to cdef.php, (2) data_input.php, (3) data_queries.php, (4) data_sources.php, (5) data_templates.php, (6) graph_templa
- CVE-2014-2709Apr 23, 2014affected < 0.8.8h-1.2fixed 0.8.8h-1.2
lib/rrd.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified parameters.
- CVE-2014-2328Apr 23, 2014affected < 0.8.8h-1.2fixed 0.8.8h-1.2
lib/graph_export.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in unspecified vectors.
- CVE-2014-2327Apr 23, 2014affected < 0.8.8h-1.2fixed 0.8.8h-1.2
Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users for unspecified commands, as demonstrated by requests that (1) modify binary files, (2) modify configurations, or (3) add arbitrary u
Page 4 of 5