Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-20724

Опубликовано: 16 янв. 2019
Источник: debian
EPSS Низкий

Описание

A cross-site scripting (XSS) vulnerability exists in pollers.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname for Data Collectors.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cactifixed1.2.1+ds1-1package
cactinot-affectedstretchpackage
cactinot-affectedjessiepackage

Примечания

  • https://github.com/Cacti/cacti/commit/1f42478506d83d188f68ce5ff41728a7bd159f53

  • https://github.com/Cacti/cacti/issues/2212

EPSS

Процентиль: 68%
0.00583
Низкий

Связанные уязвимости

CVSS3: 4.8
ubuntu
около 7 лет назад

A cross-site scripting (XSS) vulnerability exists in pollers.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname for Data Collectors.

CVSS3: 4.8
nvd
около 7 лет назад

A cross-site scripting (XSS) vulnerability exists in pollers.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname for Data Collectors.

CVSS3: 4.8
github
больше 3 лет назад

A cross-site scripting (XSS) vulnerability exists in pollers.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname for Data Collectors.

suse-cvrf
почти 6 лет назад

Security update for cacti, cacti-spine

suse-cvrf
почти 6 лет назад

Security update for cacti, cacti-spine

EPSS

Процентиль: 68%
0.00583
Низкий