Cacti Multiple Cross-Site Scripting Vulnerabilities Fixed by 1.1.13
Description
(#Updated, 17/07/2017:#The cacti packages provided by FreeBSD are vulnerable (CVE-2017-10970).#Several cross-site scripting vulnerabilities were reported in Cacti:#- CVE-2017-10970: triggerable via the "id" parameter of the "link.php" web page#- CVE-2017-11163: triggerable post-authenticated via specially crafted HTTP Referer headers in the "aggregate_graphs.php" web page##A remote attacker could exploit them by enticing their victim into following a specially crafted link in order to execute arbitrary JavaScript or HTML code.##Proofs of concept are available.)