Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
6.1
CVSSv3
CVE-2017-16785
Published: 10/11/2017 Updated: 27/11/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
Subscribe to Cacti
Vulnerability Summary
Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.
Vulnerable Product
Search on Vulmon
Subscribe to Product
cacti cacti 1.1.27
Vendor Advisories
Debian CVElist Bug Report Logs: cacti: CVE-2017-16641: arbitrary execution of os commands via path_rrdtool parameter in an action=save request
Debian Bug report logs - #881110 cacti: CVE-2017-16641: arbitrary execution of os commands via path_rrdtool parameter in an action=save request Package: src:cacti; Maintainer for src:cacti is Cacti Maintainer <pkg-cacti-maint@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 7 ...
Arch Linux Issues:
Cacti 1127 has reflected XSS via the PATH_INFO to hostphp ...
References
CWE-79
https://github.com/Cacti/cacti/issues/1071
http://www.securitytracker.com/id/1039774
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881110
https://nvd.nist.gov
https://security.archlinux.org/CVE-2017-16785
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-38028
CVE-2024-32406
CVE-2024-25624
IMAP
CVE-2024-2310
CVE-2024-0874
CVE-2024-20359
XXE
remote code execution
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started