Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-7106

Опубликовано: 16 янв. 2020
Источник: debian
EPSS Низкий

Описание

Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cactifixed1.2.9+ds1-1package
cactifixed1.2.2+ds1-2+deb10u3busterpackage

Примечания

  • https://github.com/Cacti/cacti/issues/3191

  • https://github.com/Cacti/cacti/commit/4cbb045e03ee20a2bd09094a201a925fbb8a39d9

  • https://github.com/Cacti/cacti/commit/47a000b5aba4af16967e249b25f25397506e3464

  • https://github.com/Cacti/cacti/commit/b1c70e19466a6e69284e24cde437b55ccc454bee

EPSS

Процентиль: 88%
0.04094
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 6 лет назад

Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS).

CVSS3: 6.1
nvd
около 6 лет назад

Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS).

suse-cvrf
больше 5 лет назад

Security update for cacti, cacti-spine

CVSS3: 6.1
github
больше 3 лет назад

Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS).

suse-cvrf
почти 6 лет назад

Security update for cacti, cacti-spine

EPSS

Процентиль: 88%
0.04094
Низкий