3.5
CVSSv2

CVE-2017-12066

Published: 01/08/2017 Updated: 02/08/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti prior to 1.1.16 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable. NOTE: this vulnerability exists because of an incomplete fix (lack of the htmlspecialchars ENT_QUOTES flag) for CVE-2017-11163.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cacti cacti

Vendor Advisories

Debian Bug report logs - #870353 cacti: CVE-2017-12065 Package: src:cacti; Maintainer for src:cacti is Cacti Maintainer <pkg-cacti-maint@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 1 Aug 2017 11:33:01 UTC Severity: important Tags: patch, security, upstream Found in ver ...
Debian Bug report logs - #870354 cacti: CVE-2017-12066 Package: src:cacti; Maintainer for src:cacti is Cacti Maintainer <pkg-cacti-maint@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 1 Aug 2017 11:36:01 UTC Severity: important Tags: patch, security, upstream Found in ver ...
spikekillphp in Cacti before 1116 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter (CVE-2017-12065) Cross-site scripting (XSS) vulnerability in aggregate_graphsphp in Cacti before 1116 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted H ...