First published: Tue Aug 01 2017(Updated: )
spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti | <=1.1.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12065 is considered a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2017-12065, upgrade Cacti to version 1.1.16 or later.
CVE-2017-12065 affects Cacti versions prior to 1.1.16.
CVE-2017-12065 allows remote attackers to execute arbitrary code on the affected Cacti installations.
The parameters exploited in CVE-2017-12065 include avgnan, outlier-start, and outlier-end.