Описание
Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used).
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| cacti | fixed | 1.1.37+ds1-1 | package | |
| cacti | no-dsa | jessie | package | |
| cacti | no-dsa | wheezy | package |
Примечания
https://github.com/Cacti/cacti/issues/1457
https://github.com/Cacti/cacti/commit/3ba47881c5f8f6a01606a5afd4f1934e32d97e92 (v1.1.37)
https://github.com/Cacti/cacti/commit/1f1b353b2e5ac9380cbea06dd9f6f8a20133379d (v1.1.37)
https://github.com/Cacti/cacti/commit/cb57a6e87751fbc6645bde1f8c16d9dca3765c4a (v1.1.37)
https://github.com/Cacti/cacti/commit/0730ce38735d146de098fc450c4420c1a3fbdf95 (v1.1.37)
https://github.com/Cacti/cacti/commit/0eb5a973c9b563b1f8c9e1d181baef06c0e89d56 (v1.1.37)
https://github.com/Cacti/cacti/commit/3a76892c178e27ce6e7189fd0ba17581f91154e8 (v1.1.37)
Связанные уязвимости
Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used).
Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used).
Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used).