Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-11163

Опубликовано: 10 июл. 2017
Источник: debian
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cactifixed1.1.12+ds1-1package
cactinot-affectedstretchpackage
cactinot-affectedjessiepackage
cactinot-affectedwheezypackage

Примечания

  • https://github.com/Cacti/cacti/issues/847

  • aggregate_graphs.php not available in 0.8.8.

  • Upstream claims fix for CVE-2017-10970 also fixes this CVE

  • but produced this patch anyway: https://github.com/Cacti/cacti/commit/bf5b1309dcf68578c3bdc4db54112dfb2e8ec4f4

EPSS

Процентиль: 45%
0.00223
Низкий

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 8 лет назад

Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable.

CVSS3: 5.4
nvd
больше 8 лет назад

Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable.

CVSS3: 5.4
github
больше 3 лет назад

Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable.

suse-cvrf
больше 8 лет назад

Security update for cacti, cacti-spine

EPSS

Процентиль: 45%
0.00223
Низкий