CVE-2018-10059
12.04.2018, 16:29
Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER['PHP_SELF'] instead of $_SERVER['SCRIPT_NAME'] to determine a page name.
Vendor | Product | Version |
---|---|---|
cacti | cacti | 𝑥 ≤ 1.1.36 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases