Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2017.0267
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2017-0267)
Resumen:The remote host is missing an update for the 'cacti' package(s) announced via the MGASA-2017-0267 advisory.
Descripción:Summary:
The remote host is missing an update for the 'cacti' package(s) announced via the MGASA-2017-0267 advisory.

Vulnerability Insight:
Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12
allows remote anonymous users to inject arbitrary web script or HTML
via the id parameter, related to the die_html_input_error function in
lib/html_validate.php (CVE-2017-10970).

Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in
Cacti 1.1.12 allows remote authenticated users to inject arbitrary web
script or HTML via specially crafted HTTP Referer headers, related to
the $cancel_url variable (CVE-2017-11163).

A Cross-site scripting vulnerability exists in cacti before 1.1.14 in
the user profile management page (auth_profile.php), allowing inject
arbitrary web script or HTML via specially crafted HTTP Referer headers
(CVE-2017-11691).

spikekill.php in Cacti before 1.1.16 might allow remote attackers to
execute arbitrary code via the avgnan, outlier-start, or outlier-end
parameter (CVE-2017-12065).

Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in
Cacti before 1.1.16 allows remote authenticated users to inject
arbitrary web script or HTML via specially crafted HTTP Referer headers,
related to the $cancel_url variable (CVE-2017-12066).

Affected Software/OS:
'cacti' package(s) on Mageia 6.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2017-10970
http://www.securitytracker.com/id/1038908
Common Vulnerability Exposure (CVE) ID: CVE-2017-11163
Common Vulnerability Exposure (CVE) ID: CVE-2017-11691
BugTraq ID: 100022
http://www.securityfocus.com/bid/100022
http://www.securitytracker.com/id/1038982
Common Vulnerability Exposure (CVE) ID: CVE-2017-12065
BugTraq ID: 100080
http://www.securityfocus.com/bid/100080
https://security.gentoo.org/glsa/201711-10
Common Vulnerability Exposure (CVE) ID: CVE-2017-12066
CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.