CVE-2017-16660

HIGH

Cacti 1.1.27 - Authenticated RCE

Title source: llm

Description

Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path under the web root, and then making a remote_agent.php request containing PHP code in a Client-ip header.

Scores

CVSS v3 7.2
EPSS 0.0146
EPSS Percentile 80.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-668
Status draft

Affected Products (1)

cacti/cacti

Timeline

Published Nov 08, 2017
Tracked Since Feb 18, 2026