Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-10061

Опубликовано: 12 апр. 2018
Источник: debian

Описание

Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cactifixed1.1.37+ds1-1package
cactino-dsajessiepackage
cactino-dsawheezypackage

Примечания

  • https://github.com/Cacti/cacti/issues/1457

  • https://github.com/Cacti/cacti/commit/3ba47881c5f8f6a01606a5afd4f1934e32d97e92 (v1.1.37)

  • https://github.com/Cacti/cacti/commit/1f1b353b2e5ac9380cbea06dd9f6f8a20133379d (v1.1.37)

  • https://github.com/Cacti/cacti/commit/cb57a6e87751fbc6645bde1f8c16d9dca3765c4a (v1.1.37)

  • https://github.com/Cacti/cacti/commit/0730ce38735d146de098fc450c4420c1a3fbdf95 (v1.1.37)

  • https://github.com/Cacti/cacti/commit/0eb5a973c9b563b1f8c9e1d181baef06c0e89d56 (v1.1.37)

  • https://github.com/Cacti/cacti/commit/3a76892c178e27ce6e7189fd0ba17581f91154e8 (v1.1.37)

Связанные уязвимости

CVSS3: 5.4
ubuntu
почти 8 лет назад

Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used).

CVSS3: 5.4
nvd
почти 8 лет назад

Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used).

CVSS3: 5.4
github
больше 3 лет назад

Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used).