cbcvebase.

Debian Cacti vulnerabilities

155 known vulnerabilities affecting debian/cacti.

Total CVEs
155
CISA KEV
1
actively exploited
Public exploits
25
Exploited in wild
3
Severity breakdown
CRITICAL10HIGH50MEDIUM72LOW23

Vulnerabilities

Page 8 of 8
CVE-2023-39516P4MEDIUMCVSS 6.1fixed in cacti 1.2.24+ds1-1+deb12u1 (bookworm)2023
CVE-2023-39516 [MEDIUM] CVE-2023-39516: cacti - Cacti is an open source operational monitoring and fault management framework. A... Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's browser at view-t
debian
CVE-2014-2326P4MEDIUMCVSS 4.3fixed in cacti 0.8.8b+dfsg-4 (bookworm)2014
CVE-2014-2326 [MEDIUM] CVE-2014-2326: cacti - Cross-site scripting (XSS) vulnerability in cdef.php in Cacti 0.8.7g, 0.8.8b, an... Cross-site scripting (XSS) vulnerability in cdef.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Scope: local bookworm: resolved (fixed in 0.8.8b+dfsg-4) bullseye: resolved (fixed in 0.8.8b+dfsg-4) forky: resolved (fixed in 0.8.8b+dfsg-4) sid: resolved (fixed in 0.8.8b+dfsg-4) trixie: res
debian
CVE-2015-2665P4MEDIUMCVSS 4.3fixed in cacti 0.8.8d+ds1-1 (bookworm)2015
CVE-2015-2665 [MEDIUM] CVE-2015-2665: cacti - Cross-site scripting (XSS) vulnerability in Cacti before 0.8.8d allows remote at... Cross-site scripting (XSS) vulnerability in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Scope: local bookworm: resolved (fixed in 0.8.8d+ds1-1) bullseye: resolved (fixed in 0.8.8d+ds1-1) forky: resolved (fixed in 0.8.8d+ds1-1) sid: resolved (fixed in 0.8.8d+ds1-1) trixie: resolved (fixed in 0.8.8d+ds1-1)
debian
CVE-2014-4002P4MEDIUMCVSS 4.3fixed in cacti 0.8.8b+dfsg-6 (bookworm)2014
CVE-2014-4002 [MEDIUM] CVE-2014-4002: cacti - Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote... Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the (1) drp_action parameter to cdef.php, (2) data_input.php, (3) data_queries.php, (4) data_sources.php, (5) data_templates.php, (6) graph_templates.php, (7) graphs.php, (8) host.php, or (9) host_templates.php or the (10) graph_templat
debian
CVE-2015-2967P4MEDIUMCVSS 4.3fixed in cacti 0.8.8d+ds1-1 (bookworm)2015
CVE-2015-2967 [MEDIUM] CVE-2015-2967: cacti - Cross-site scripting (XSS) vulnerability in settings.php in Cacti before 0.8.8d ... Cross-site scripting (XSS) vulnerability in settings.php in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Scope: local bookworm: resolved (fixed in 0.8.8d+ds1-1) bullseye: resolved (fixed in 0.8.8d+ds1-1) forky: resolved (fixed in 0.8.8d+ds1-1) sid: resolved (fixed in 0.8.8d+ds1-1) trixie: resolved (fixed i
debian
CVE-2010-2545P4MEDIUMCVSS 4.3fixed in cacti 0.8.7g-1 (bookworm)2010
CVE-2010-2545 [MEDIUM] CVE-2010-2545: cacti - Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0.8.7g, as u... Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0.8.7g, as used in Red Hat High Performance Computing (HPC) Solution and other products, allow remote attackers to inject arbitrary web script or HTML via (1) the name element in an XML template to templates_import.php; and allow remote authenticated administrators to inject arbitrary web script or HT
debian
CVE-2018-20725P4LOWCVSS 4.8fixed in cacti 1.2.1+ds1-1 (bookworm)2018
CVE-2018-20725 [MEDIUM] CVE-2018-20725: cacti - A cross-site scripting (XSS) vulnerability exists in graph_templates.php in Cact... A cross-site scripting (XSS) vulnerability exists in graph_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Graph Vertical Label. Scope: local bookworm: resolved (fixed in 1.2.1+ds1-1) bullseye: resolved (fixed in 1.2.1+ds1-1) forky: resolved (fixed in 1.2.1+ds1-1) sid: resolved (fixed in 1.2.1+ds1-1) trixie: resolved (fixe
debian
CVE-2018-20724P4LOWCVSS 4.8fixed in cacti 1.2.1+ds1-1 (bookworm)2018
CVE-2018-20724 [MEDIUM] CVE-2018-20724: cacti - A cross-site scripting (XSS) vulnerability exists in pollers.php in Cacti before... A cross-site scripting (XSS) vulnerability exists in pollers.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Website Hostname for Data Collectors. Scope: local bookworm: resolved (fixed in 1.2.1+ds1-1) bullseye: resolved (fixed in 1.2.1+ds1-1) forky: resolved (fixed in 1.2.1+ds1-1) sid: resolved (fixed in 1.2.1+ds1-1) trixie: resolv
debian
CVE-2018-20723P4LOWCVSS 4.8fixed in cacti 1.2.1+ds1-1 (bookworm)2018
CVE-2018-20723 [MEDIUM] CVE-2018-20723: cacti - A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cact... A cross-site scripting (XSS) vulnerability exists in color_templates.php in Cacti before 1.2.0 due to lack of escaping of unintended characters in the Name field for a Color. Scope: local bookworm: resolved (fixed in 1.2.1+ds1-1) bullseye: resolved (fixed in 1.2.1+ds1-1) forky: resolved (fixed in 1.2.1+ds1-1) sid: resolved (fixed in 1.2.1+ds1-1) trixie: resolved (fi
debian
CVE-2010-1644P4MEDIUMCVSS 4.3fixed in cacti 0.8.7g-1 (bookworm)2010
CVE-2010-1644 [MEDIUM] CVE-2010-1644: cacti - Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0.8.7f, as u... Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products, allow remote attackers to inject arbitrary web script or HTML via the (1) hostname or (2) description parameter to host.php, or (3) the host_id parameter to data_sources.php. Scope: local bookworm: resolved (fixed
debian
CVE-2013-5588P4MEDIUMCVSS 4.3fixed in cacti 0.8.8b+dfsg-3 (bookworm)2013
CVE-2013-5588 [MEDIUM] CVE-2013-5588: cacti - Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b and earlier ... Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the step parameter to install/index.php or (2) the id parameter to cacti/host.php. Scope: local bookworm: resolved (fixed in 0.8.8b+dfsg-3) bullseye: resolved (fixed in 0.8.8b+dfsg-3) forky: resolved (fixed in 0.8.8b+dfs
debian
CVE-2014-5026P4LOWCVSS 3.5fixed in cacti 0.8.8b+dfsg-7 (bookworm)2014
CVE-2014-5026 [LOW] CVE-2014-5026: cacti - Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote... Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote authenticated users with console access to inject arbitrary web script or HTML via a (1) Graph Tree Title in a delete or (2) edit action; (3) CDEF Name, (4) Data Input Method Name, or (5) Host Templates Name in a delete action; (6) Data Source Title; (7) Graph Title; or (8) Graph Template Na
debian
CVE-2004-1736P4MEDIUMCVSS 5.0fixed in cacti 0.8.5a-5 (bookworm)2004
CVE-2004-1736 [MEDIUM] CVE-2004-1736: cacti - Cacti 0.8.5a allows remote attackers to gain sensitive information via an HTTP r... Cacti 0.8.5a allows remote attackers to gain sensitive information via an HTTP request to (1) auth.php, (2) auth_login.php, (3) auth_changepassword.php, and possibly other php files, which reveal the installation path in a PHP error message. Scope: local bookworm: resolved (fixed in 0.8.5a-5) bullseye: resolved (fixed in 0.8.5a-5) forky: resolved (fixed in 0.8.5a-5) s
debian
CVE-2014-5025P4LOWCVSS 3.5fixed in cacti 0.8.8b+dfsg-7 (bookworm)2014
CVE-2014-5025 [LOW] CVE-2014-5025: cacti - Cross-site scripting (XSS) vulnerability in data_sources.php in Cacti 0.8.8b all... Cross-site scripting (XSS) vulnerability in data_sources.php in Cacti 0.8.8b allows remote authenticated users with console access to inject arbitrary web script or HTML via the name_cache parameter in a ds_edit action. Scope: local bookworm: resolved (fixed in 0.8.8b+dfsg-7) bullseye: resolved (fixed in 0.8.8b+dfsg-7) forky: resolved (fixed in 0.8.8b+dfsg-7) sid: resolv
debian
CVE-2002-1479P4MEDIUMCVSS 4.6fixed in cacti 0.6.8-1 (bookworm)2002
CVE-2002-1479 [MEDIUM] CVE-2002-1479: cacti - Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.p... Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users to modify databases as the Cacti user and possibly gain privileges. Scope: local bookworm: resolved (fixed in 0.6.8-1) bullseye: resolved (fixed in 0.6.8-1) forky: resolved (fixed in 0.6.8-1) sid: resolved (fixed in 0.6.8-1
debian
Debian Cacti vulnerabilities | cvebase