Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-16660

Опубликовано: 08 нояб. 2017
Источник: debian

Описание

Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path under the web root, and then making a remote_agent.php request containing PHP code in a Client-ip header.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cactifixed1.1.27+ds1-3package
cactinot-affectedstretchpackage
cactinot-affectedjessiepackage
cactinot-affectedwheezypackage

Примечания

  • https://github.com/Cacti/cacti/issues/1066

  • affected code was introduced in the 1.x release

Связанные уязвимости

CVSS3: 7.2
ubuntu
около 8 лет назад

Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path under the web root, and then making a remote_agent.php request containing PHP code in a Client-ip header.

CVSS3: 7.2
nvd
около 8 лет назад

Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path under the web root, and then making a remote_agent.php request containing PHP code in a Client-ip header.

CVSS3: 7.2
github
больше 3 лет назад

Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path under the web root, and then making a remote_agent.php request containing PHP code in a Client-ip header.

suse-cvrf
около 8 лет назад

Security update for cacti, cacti-spine