Total vulnerabilities in the database
Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER['PHP_SELF'] instead of $_SERVER['SCRIPT_NAME'] to determine a page name.
Software | From | Fixed in |
---|---|---|
cacti / cacti | - | 1.1.36.x |