CVE-2017-16660

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/11/2017
Last modified:
20/04/2025

Description

Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path under the web root, and then making a remote_agent.php request containing PHP code in a Client-ip header.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cacti:cacti:1.1.27:*:*:*:*:*:*:*