PT-2017-14509 · Cacti+1 · Cacti+1

Hex0Wn

·

Published

2017-11-08

·

Updated

2024-06-15

·

CVE-2017-16661

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cacti version 1.1.27
Description The issue allows remote authenticated administrators to read arbitrary files. This can be achieved by modifying the Log Path to point to a private directory and then making a request to "clog.php?filename=" with the desired file, such as 'filename=passwd' to read '/etc/passwd'.
Recommendations For Cacti version 1.1.27, restrict access to the clog.php file and limit the ability to modify the Log Path to prevent unauthorized file reading. As a temporary workaround, consider restricting the filename parameter in the clog.php request to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-16661
OPENSUSE-SU-2017_3051-1
OPENSUSE-SU-2024:10670-1

Affected Products

Cacti
Suse