cigamit
10 exploits
Active since Jul 2017
Cacti < 1.1.17 - Authenticated Cross-Site Scripting via External Link Title Field
CVSS 5.4
Cacti <= 1.2.7 - Authenticated Unsafe Deserialization in lib/functions.php
CVSS 8.1
Cacti 1.1.13 - Cross-Site Scripting via HTTP Referer Header
CVSS 5.4
Cacti < 1.1.16 - Remote Code Execution via spikekill.php Parameter Injection
CVSS 9.8
Cacti < 1.1.16 - Authenticated Stored Cross-Site Scripting via HTTP Referer Header
CVSS 5.4
Cacti 1.1.17 - Cross-Site Scripting via spikekill.php Method Parameter
CVSS 6.1
Cacti < 1.2.0 - Stored Cross-Site Scripting in Color Name Field
CVSS 4.8
Cacti < 1.2.0 - Stored Cross-Site Scripting in Website Hostname for Data Collectors
CVSS 4.8
Cacti < 1.2.0 - Stored Cross-Site Scripting in Graph Vertical Label
CVSS 4.8
Cacti < 1.2.0 - Stored Cross-Site Scripting via Website Hostname Field
CVSS 5.4