Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-20726

Опубликовано: 16 янв. 2019
Источник: nvd
CVSS3: 5.4
CVSS2: 3.5
EPSS Низкий

Описание

A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname field for Devices.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*
Версия до 1.2.0 (исключая)

EPSS

Процентиль: 66%
0.0051
Низкий

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 7 лет назад

A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname field for Devices.

CVSS3: 5.4
debian
около 7 лет назад

A cross-site scripting (XSS) vulnerability exists in host.php (via tre ...

CVSS3: 5.4
github
больше 3 лет назад

A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname field for Devices.

suse-cvrf
почти 6 лет назад

Security update for cacti, cacti-spine

suse-cvrf
почти 6 лет назад

Security update for cacti, cacti-spine

EPSS

Процентиль: 66%
0.0051
Низкий

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79