Related Vulnerabilities: CVE-2017-16785  

Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.

Severity High

Remote Yes

Type Cross-site scripting

Description

Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.

AVG-537 cacti 1.1.17-1 1.1.28-1 High Fixed

02 Dec 2017 ASA-201712-2 AVG-537 cacti High multiple issues

https://github.com/Cacti/cacti/issues/1071