Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-12978

Опубликовано: 21 авг. 2017
Источник: debian

Описание

lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cactifixed1.1.18+ds1-1package
cactinot-affectedstretchpackage
cactinot-affectedjessiepackage
cactinot-affectedwheezypackage

Примечания

  • https://github.com/Cacti/cacti/commit/9c610a7a4e29595dcaf7d7082134e4b89619ea24

  • https://github.com/Cacti/cacti/issues/918

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 8 лет назад

lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.

CVSS3: 5.4
nvd
больше 8 лет назад

lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.

CVSS3: 5.4
github
больше 3 лет назад

lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.

suse-cvrf
больше 8 лет назад

Security update for cacti, cacti-spine