ALAS-2017-874 ---- cactiID: oval:org.secpod.oval:def:1600749 | Date: (C)2020-11-27 (M)2023-04-19 |
Class: PATCH | Family: unix |
spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter. Cross-site scripting vulnerability in aggregate_graphs.php in Cacti before 1.1.16 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-11163
Platform: |
Amazon Linux AMI |