The Cacti Group
8 exploits
Active since Dec 2019
Cacti < 1.2.25 - Authenticated SQL Injection via pollers.php
CVSS 8.8
Cacti 1.2.25 - Authenticated Blind SQL Injection via SNMP Notification Receivers
CVSS 8.8
Cacti 1.3.x DEV - Command Injection
CVSS 10.0
Cacti 1.3.x DEV - Reflected Cross-Site Scripting
CVSS 6.1
Cacti <= 1.2.7 - Authenticated Unsafe Deserialization in lib/functions.php
CVSS 8.1
Cacti < 1.2.25 - Authenticated Stored Cross-Site Scripting in data_debug.php
CVSS 6.1
Cacti 1.2.25 - Reflected Cross-Site Scripting in XML Template Import Error Message
CVSS 5.4
Cacti < 1.2.27 - Authenticated SQL Injection via api_automation.php filter Parameter
CVSS 8.8