Oval Definition:oval:com.ubuntu.bionic:def:2017120660000000
Revision Date:2017-08-01Version:1
Title:CVE-2017-12066 on Ubuntu 18.04 LTS (bionic) - medium.
Description:Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti before 1.1.16 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable. NOTE: this vulnerability exists because of an incomplete fix (lack of the htmlspecialchars ENT_QUOTES flag) for CVE-2017-11163.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2017-12066
Platform(s):Ubuntu 18.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 18.04 LTS (bionic) is installed.
  • AND cacti package in bionic, is related to the CVE in some way and has been fixed (note: '1.1.38+ds1-1').
  • BACK