Vulnerabilities
Vulnerable Software
Cacti:  >> Cacti  >> 1.2.2  Security Vulnerabilities
Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions taken by Cacti or potentially cause memory corruption in the PHP module.
CVSS Score
8.1
EPSS Score
0.03
Published
2019-12-12
In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_json.php request with a modified local_graph_id parameter.
CVSS Score
4.3
EPSS Score
0.015
Published
2019-09-23
In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP community string (SNMP Options) in the View poller cache, leading to XSS.
CVSS Score
5.4
EPSS Score
0.013
Published
2019-04-08


Contact Us

Shodan ® - All rights reserved