Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2017.0267
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2017-0267)
Zusammenfassung:The remote host is missing an update for the 'cacti' package(s) announced via the MGASA-2017-0267 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'cacti' package(s) announced via the MGASA-2017-0267 advisory.

Vulnerability Insight:
Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12
allows remote anonymous users to inject arbitrary web script or HTML
via the id parameter, related to the die_html_input_error function in
lib/html_validate.php (CVE-2017-10970).

Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in
Cacti 1.1.12 allows remote authenticated users to inject arbitrary web
script or HTML via specially crafted HTTP Referer headers, related to
the $cancel_url variable (CVE-2017-11163).

A Cross-site scripting vulnerability exists in cacti before 1.1.14 in
the user profile management page (auth_profile.php), allowing inject
arbitrary web script or HTML via specially crafted HTTP Referer headers
(CVE-2017-11691).

spikekill.php in Cacti before 1.1.16 might allow remote attackers to
execute arbitrary code via the avgnan, outlier-start, or outlier-end
parameter (CVE-2017-12065).

Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in
Cacti before 1.1.16 allows remote authenticated users to inject
arbitrary web script or HTML via specially crafted HTTP Referer headers,
related to the $cancel_url variable (CVE-2017-12066).

Affected Software/OS:
'cacti' package(s) on Mageia 6.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2017-10970
http://www.securitytracker.com/id/1038908
Common Vulnerability Exposure (CVE) ID: CVE-2017-11163
Common Vulnerability Exposure (CVE) ID: CVE-2017-11691
BugTraq ID: 100022
http://www.securityfocus.com/bid/100022
http://www.securitytracker.com/id/1038982
Common Vulnerability Exposure (CVE) ID: CVE-2017-12065
BugTraq ID: 100080
http://www.securityfocus.com/bid/100080
https://security.gentoo.org/glsa/201711-10
Common Vulnerability Exposure (CVE) ID: CVE-2017-12066
CopyrightCopyright (C) 2022 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.