Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2017-16785

Disclosure Date: November 10, 2017 (last updated November 26, 2024)
Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.
0
Attacker Value
Unknown

CVE-2017-16661

Disclosure Date: November 08, 2017 (last updated November 26, 2024)
Cacti 1.1.27 allows remote authenticated administrators to read arbitrary files by placing the Log Path into a private directory, and then making a clog.php?filename= request, as demonstrated by filename=passwd (with a Log Path under /etc) to read /etc/passwd.
0
Attacker Value
Unknown

CVE-2017-16660

Disclosure Date: November 08, 2017 (last updated November 26, 2024)
Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path under the web root, and then making a remote_agent.php request containing PHP code in a Client-ip header.
0
Attacker Value
Unknown

CVE-2017-16641

Disclosure Date: November 07, 2017 (last updated November 26, 2024)
lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execute arbitrary OS commands via the path_rrdtool parameter in an action=save request to settings.php.
0