Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-11163

Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 45.0%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2017-11163
  • Cacti » Cacti » Version: 1.1.12
    cpe:2.3:a:cacti:cacti:1.1.12


Contact Us

Shodan ® - All rights reserved