Vulnerabilities
Vulnerable Software
Cacti:  >> Cacti  >> 1.2.8  Security Vulnerabilities
In Cacti before 1.2.11, auth_profile.php?action=edit allows CSRF for an admin email change.
CVSS Score
6.5
EPSS Score
0.005
Published
2020-05-20
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege.
CVSS Score
8.8
EPSS Score
0.941
Published
2020-02-22
Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation.php. OS commands are executed when a new poller cycle begins. The attacker must be authenticated, and must have access to modify the Performance Settings of the product.
CVSS Score
8.8
EPSS Score
0.468
Published
2020-01-20
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS).
CVSS Score
6.1
EPSS Score
0.041
Published
2020-01-16
data_input.php in Cacti 1.2.8 allows remote code execution via a crafted Input String to Data Collection -> Data Input Methods -> Unix -> Ping Host. NOTE: the vendor has stated "This is a false alarm.
CVSS Score
8.8
EPSS Score
0.009
Published
2020-01-15


Contact Us

Shodan ® - All rights reserved