Vulnerabilities
Vulnerable Software
Cacti:  >> Cacti  >> 1.1.37  Security Vulnerabilities
In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache, leading to XSS.
CVSS Score
5.4
EPSS Score
0.013
Published
2019-04-08
A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Name field for a Color.
CVSS Score
4.8
EPSS Score
0.01
Published
2019-01-16
A cross-site scripting (XSS) vulnerability exists in pollers.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname for Data Collectors.
CVSS Score
4.8
EPSS Score
0.01
Published
2019-01-16
A cross-site scripting (XSS) vulnerability exists in graph_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Graph Vertical Label.
CVSS Score
4.8
EPSS Score
0.01
Published
2019-01-16
A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname field for Devices.
CVSS Score
5.4
EPSS Score
0.01
Published
2019-01-16


Contact Us

Shodan ® - All rights reserved