{"id":"MGASA-2017-0267","summary":"Updated cacti packages fix security vulnerabilities","details":"Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12\nallows remote anonymous users to inject arbitrary web script or HTML\nvia the id parameter, related to the die_html_input_error function in\nlib/html_validate.php (CVE-2017-10970).\n\nCross-site scripting (XSS) vulnerability in aggregate_graphs.php in\nCacti 1.1.12 allows remote authenticated users to inject arbitrary web\nscript or HTML via specially crafted HTTP Referer headers, related to\nthe $cancel_url variable (CVE-2017-11163).\n\nA Cross-site scripting vulnerability exists in cacti before 1.1.14 in\nthe user profile managment page (auth_profile.php), allowing inject\narbitrary web script or HTML via specially crafted HTTP Referer headers\n(CVE-2017-11691).\n\nspikekill.php in Cacti before 1.1.16 might allow remote attackers to\nexecute arbitrary code via the avgnan, outlier-start, or outlier-end\nparameter (CVE-2017-12065).\n\nCross-site scripting (XSS) vulnerability in aggregate_graphs.php in\nCacti before 1.1.16 allows remote authenticated users to inject\narbitrary web script or HTML via specially crafted HTTP Referer headers,\nrelated to the $cancel_url variable (CVE-2017-12066).\n","modified":"2026-04-16T06:25:36.298974749Z","published":"2017-08-13T22:19:29Z","upstream":["CVE-2017-10970","CVE-2017-11163","CVE-2017-11691","CVE-2017-12065","CVE-2017-12066"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2017-0267.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=21242"},{"type":"WEB","url":"https://www.cacti.net/changelog.php"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/7MRJCGVNDLW7RCTYSL72XGP74PCMOIH2/"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2017/07/27/1"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/QN75M6HGIKEEX7HYFWHIO6IYDB5RXFP6/"},{"type":"WEB","url":"https://lists.opensuse.org/opensuse-updates/2017-08/msg00018.html"}],"affected":[{"package":{"name":"cacti","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/cacti?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.16-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2017-0267.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}