6.1
CVSSv3

CVE-2017-15194

Published: 11/10/2017 Updated: 20/10/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2) the refresh page.

Vulnerable Product Search on Vulmon Subscribe to Product

cacti cacti 1.1.25

Vendor Advisories

Debian Bug report logs - #881110 cacti: CVE-2017-16641: arbitrary execution of os commands via path_rrdtool parameter in an action=save request Package: src:cacti; Maintainer for src:cacti is Cacti Maintainer <pkg-cacti-maint@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 7 ...
Debian Bug report logs - #878304 cacti: CVE-2017-15194 Package: src:cacti; Maintainer for src:cacti is Cacti Maintainer <pkg-cacti-maint@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 12 Oct 2017 14:27:02 UTC Severity: important Tags: patch, security, upstream Found in ver ...
include/global_sessionphp in Cacti 1125 has XSS related to (1) the URI or (2) the refresh page (CVE-2017-15194) ...