First published: Wed Nov 15 2017(Updated: )
Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object, related to calling unserialize(stripslashes()).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/cacti | 1.2.2+ds1-2+deb10u4 1.2.2+ds1-2+deb10u5 1.2.16+ds1-2+deb11u1 1.2.24+ds1-1 1.2.25+ds1-2 | |
Cacti Cacti | <1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.