Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-12978

Опубликовано: 21 авг. 2017
Источник: debian
EPSS Низкий

Описание

lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cactifixed1.1.18+ds1-1package
cactinot-affectedstretchpackage
cactinot-affectedjessiepackage
cactinot-affectedwheezypackage

Примечания

  • https://github.com/Cacti/cacti/commit/9c610a7a4e29595dcaf7d7082134e4b89619ea24

  • https://github.com/Cacti/cacti/issues/918

EPSS

Процентиль: 53%
0.00789
Низкий

Связанные уязвимости

CVSS3: 5.4
ubuntu
почти 9 лет назад

lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.

CVSS3: 5.4
nvd
почти 9 лет назад

lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.

CVSS3: 5.4
github
больше 4 лет назад

lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.

suse-cvrf
почти 9 лет назад

Security update for cacti, cacti-spine

EPSS

Процентиль: 53%
0.00789
Низкий