Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-16661

Опубликовано: 08 нояб. 2017
Источник: debian

Описание

Cacti 1.1.27 allows remote authenticated administrators to read arbitrary files by placing the Log Path into a private directory, and then making a clog.php?filename= request, as demonstrated by filename=passwd (with a Log Path under /etc) to read /etc/passwd.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cactifixed1.1.27+ds1-3package
cactinot-affectedstretchpackage
cactinot-affectedjessiepackage
cactinot-affectedwheezypackage

Примечания

  • https://github.com/Cacti/cacti/issues/1066

  • affected code was introduced in the 1.x release

Связанные уязвимости

CVSS3: 4.9
ubuntu
около 8 лет назад

Cacti 1.1.27 allows remote authenticated administrators to read arbitrary files by placing the Log Path into a private directory, and then making a clog.php?filename= request, as demonstrated by filename=passwd (with a Log Path under /etc) to read /etc/passwd.

CVSS3: 4.9
nvd
около 8 лет назад

Cacti 1.1.27 allows remote authenticated administrators to read arbitrary files by placing the Log Path into a private directory, and then making a clog.php?filename= request, as demonstrated by filename=passwd (with a Log Path under /etc) to read /etc/passwd.

CVSS3: 4.9
github
больше 3 лет назад

Cacti 1.1.27 allows remote authenticated administrators to read arbitrary files by placing the Log Path into a private directory, and then making a clog.php?filename= request, as demonstrated by filename=passwd (with a Log Path under /etc) to read /etc/passwd.

suse-cvrf
около 8 лет назад

Security update for cacti, cacti-spine