Debian Cacti vulnerabilities
155 known vulnerabilities affecting debian/cacti.
Total CVEs
155
CISA KEV
1
actively exploited
Public exploits
25
Exploited in wild
3
Severity breakdown
CRITICAL10HIGH50MEDIUM72LOW23
Vulnerabilities
Page 7 of 8
CVE-2017-15194P4MEDIUMCVSS 6.1fixed in cacti 1.1.25+ds1-1 (bookworm)2017
CVE-2017-15194 [MEDIUM] CVE-2017-15194: cacti - include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2)...
include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2) the refresh page.
Scope: local
bookworm: resolved (fixed in 1.1.25+ds1-1)
bullseye: resolved (fixed in 1.1.25+ds1-1)
forky: resolved (fixed in 1.1.25+ds1-1)
sid: resolved (fixed in 1.1.25+ds1-1)
trixie: resolved (fixed in 1.1.25+ds1-1)
debian
CVE-2017-1000032P4MEDIUMCVSS 6.1fixed in cacti 0.8.8b+dfsg-6 (bookworm)2017
CVE-2017-1000032 [MEDIUM] CVE-2017-1000032: cacti - Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attacker...
Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter to tree.php and drp_action parameter to data_sources.php.
Scope: local
bookworm: resolved (fixed in 0.8.8b+dfsg-6)
bullseye: resolved (fixed in 0.8.8b+dfsg-6)
forky: resolved (fixed in 0.8.8b+dfsg-6)
sid: resolved (
debian
CVE-2017-11163P4MEDIUMCVSS 5.4fixed in cacti 1.1.12+ds1-1 (bookworm)2017
CVE-2017-11163 [MEDIUM] CVE-2017-11163: cacti - Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12...
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable.
Scope: local
bookworm: resolved (fixed in 1.1.12+ds1-1)
bullseye: resolved (fixed in 1.1.12+ds1-1)
forky: resolved (fixed in 1.1.12+d
debian
CVE-2008-0784P4LOWCVSS 5.0fixed in cacti 0.8.7b-1 (bookworm)2008
CVE-2008-0784 [MEDIUM] CVE-2008-0784: cacti - graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allows remote att...
graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allows remote attackers to obtain the full path via an invalid local_graph_id parameter and other unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.8.7b-1)
bullseye: resolved (fixed in 0.8.7b-1)
forky: resolved (fixed in 0.8.7b-1)
sid: resolved (fixed in 0.8.7b-1)
trixie: resolved (fixed in
debian
CVE-2018-10059P4MEDIUMCVSS 5.4fixed in cacti 1.1.37+ds1-1 (bookworm)2018
CVE-2018-10059 [MEDIUM] CVE-2018-10059: cacti - Cacti before 1.1.37 has XSS because the get_current_page function in lib/functio...
Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER['PHP_SELF'] instead of $_SERVER['SCRIPT_NAME'] to determine a page name.
Scope: local
bookworm: resolved (fixed in 1.1.37+ds1-1)
bullseye: resolved (fixed in 1.1.37+ds1-1)
forky: resolved (fixed in 1.1.37+ds1-1)
sid: resolved (fixed in 1.1.37+ds1-1)
trixie: reso
debian
CVE-2018-10061P4LOWCVSS 5.4fixed in cacti 1.1.37+ds1-1 (bookworm)2018
CVE-2018-10061 [MEDIUM] CVE-2018-10061: cacti - Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls with...
Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used).
Scope: local
bookworm: resolved (fixed in 1.1.37+ds1-1)
bullseye: resolved (fixed in 1.1.37+ds1-1)
forky: resolved (fixed in 1.1.37+ds1-1)
sid: resolved (fixed in 1.1.37+ds1-1)
trixie:
debian
CVE-2017-12978P4MEDIUMCVSS 5.4fixed in cacti 1.1.18+ds1-1 (bookworm)2017
CVE-2017-12978 [MEDIUM] CVE-2017-12978: cacti - lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external l...
lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.
Scope: local
bookworm: resolved (fixed in 1.1.18+ds1-1)
bullseye: resolved (fixed in 1.1.18+ds1-1)
forky: resolved (fixed in 1.1.18+ds1-1)
sid: resolved (fixed in 1.1.18+ds1-1)
trixie: resolved (fixed in 1.1.18+ds1-1)
debian
CVE-2008-0786P4MEDIUMCVSS 4.3fixed in cacti 0.8.7b-1 (bookworm)2008
CVE-2008-0786 [MEDIUM] CVE-2008-0786: cacti - CRLF injection vulnerability in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6...
CRLF injection vulnerability in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k, when running on older PHP interpreters, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.8.7b-1)
bullseye: resolved (fixed in 0.8.7b-1)
forky: resolved (fixed in 0.8.
debian
CVE-2017-16785P4MEDIUMCVSS 6.1fixed in cacti 1.1.27+ds1-3 (bookworm)2017
CVE-2017-16785 [MEDIUM] CVE-2017-16785: cacti - Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.
Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.
Scope: local
bookworm: resolved (fixed in 1.1.27+ds1-3)
bullseye: resolved (fixed in 1.1.27+ds1-3)
forky: resolved (fixed in 1.1.27+ds1-3)
sid: resolved (fixed in 1.1.27+ds1-3)
trixie: resolved (fixed in 1.1.27+ds1-3)
debian
CVE-2017-10970P4MEDIUMCVSS 5.4fixed in cacti 1.1.12+ds1-1 (bookworm)2017
CVE-2017-10970 [MEDIUM] CVE-2017-10970: cacti - Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remo...
Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remote anonymous users to inject arbitrary web script or HTML via the id parameter, related to the die_html_input_error function in lib/html_validate.php.
Scope: local
bookworm: resolved (fixed in 1.1.12+ds1-1)
bullseye: resolved (fixed in 1.1.12+ds1-1)
forky: resolved (fixed in 1.1.12+ds1-1
debian
CVE-2023-49088P4MEDIUMCVSS 6.1fixed in cacti 1.2.24+ds1-1+deb12u2 (bookworm)2023
CVE-2023-49088 [MEDIUM] CVE-2023-49088: cacti - Cacti is an open source operational monitoring and fault management framework. T...
Cacti is an open source operational monitoring and fault management framework. The fix applied for CVE-2023-39515 in version 1.2.25 is incomplete as it enables an adversary to have a victim browser execute malicious code when a victim user hovers their mouse over the malicious data source path in `data_debug.php`. To perform the cross-site scripting attack, the adve
debian
CVE-2007-3113P4LOWCVSS 7.8fixed in cacti 0.8.6j-1.1 (bookworm)2007
CVE-2007-3113 [HIGH] CVE-2007-3113: cacti - Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to ...
Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_height or (2) graph_width parameter, different vectors than CVE-2007-3112.
Scope: local
bookworm: resolved (fixed in 0.8.6j-1.1)
bullseye: resolved (fixed in 0.8.6j-1.1)
forky: resolved (fixed in 0.8.6j-1.1)
sid:
debian
CVE-2023-39366P4MEDIUMCVSS 6.1fixed in cacti 1.2.24+ds1-1+deb12u1 (bookworm)2023
CVE-2023-39366 [MEDIUM] CVE-2023-39366: cacti - Cacti is an open source operational monitoring and fault management framework. A...
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-time. T
debian
CVE-2023-39510P4MEDIUMCVSS 6.1fixed in cacti 1.2.24+ds1-1+deb12u1 (bookworm)2023
CVE-2023-39510 [MEDIUM] CVE-2023-39510: cacti - Cacti is an open source operational monitoring and fault management framework. A...
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-time. T
debian
CVE-2023-39511P4MEDIUMCVSS 6.1fixed in cacti 1.2.24+ds1-1+deb12u1 (bookworm)2023
CVE-2023-39511 [MEDIUM] CVE-2023-39511: cacti - Cacti is an open source operational monitoring and fault management framework. A...
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-t
debian
CVE-2024-29894P4MEDIUMCVSS 5.4fixed in cacti 1.2.24+ds1-1+deb12u3 (bookworm)2024
CVE-2024-29894 [MEDIUM] CVE-2024-29894: cacti - Cacti provides an operational monitoring and fault management framework. Version...
Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete fix for CVE-2023-50250. `raise_message_javascript` from `lib/functions.php` now uses purify.js to fix CVE-2023-50250 (among others). However, it still generates the code out of unesca
debian
CVE-2011-5223P4LOWCVSS 4.3fixed in cacti 0.8.7i-1 (bookworm)2011
CVE-2011-5223 [MEDIUM] CVE-2011-5223: cacti - Cross-site request forgery (CSRF) vulnerability in logout.php in Cacti before 0....
Cross-site request forgery (CSRF) vulnerability in logout.php in Cacti before 0.8.7i allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Scope: local
bookworm: resolved (fixed in 0.8.7i-1)
bullseye: resolved (fixed in 0.8.7i-1)
forky: resolved (fixed in 0.8.7i-1)
sid: resolved (fixed in 0.8.7i-1)
trixie: resolved (fixed in
debian
CVE-2020-13230P4MEDIUMCVSS 4.3fixed in cacti 1.2.11+ds1-1 (bookworm)2020
CVE-2020-13230 [MEDIUM] CVE-2020-13230: cacti - In Cacti before 1.2.11, disabling a user account does not immediately invalidate...
In Cacti before 1.2.11, disabling a user account does not immediately invalidate any permissions granted to that account (e.g., permission to view logs).
Scope: local
bookworm: resolved (fixed in 1.2.11+ds1-1)
bullseye: resolved (fixed in 1.2.11+ds1-1)
forky: resolved (fixed in 1.2.11+ds1-1)
sid: resolved (fixed in 1.2.11+ds1-1)
trixie: resolved (fixed in 1.2.11+ds1
debian
CVE-2023-39512P4MEDIUMCVSS 6.1fixed in cacti 1.2.24+ds1-1+deb12u1 (bookworm)2023
CVE-2023-39512 [MEDIUM] CVE-2023-39512: cacti - Cacti is an open source operational monitoring and fault management framework. A...
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-t
debian
CVE-2023-39515P4MEDIUMCVSS 6.1fixed in cacti 1.2.24+ds1-1+deb12u1 (bookworm)2023
CVE-2023-39515 [MEDIUM] CVE-2023-39515: cacti - Cacti is an open source operational monitoring and fault management framework. A...
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the cacti's database. These data will be viewed by administrative cacti accounts and execute JavaScript code in the victim's browser at view-time. The s
debian