CVE-2017-16661: Infoleak
Cacti 1.1.27 allows remote authenticated administrators to read arbitrary files by placing the Log Path into a private directory, and then making a clog.php?filename= request, as demonstrated by filename=passwd (with a Log Path under /etc) to read /etc/passwd.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16661?
CVE-2017-16661 has a medium severity rating, as it allows access to sensitive files by authenticated users.
How do I fix CVE-2017-16661?
To fix CVE-2017-16661, upgrade to Cacti version 1.1.28 or later to ensure the vulnerability is patched.
Who is affected by CVE-2017-16661?
CVE-2017-16661 affects installations of Cacti version 1.1.27 that allow remote authenticated access.
What type of vulnerability is CVE-2017-16661?
CVE-2017-16661 is a file read vulnerability that can expose sensitive information to authenticated users.
What can attackers do with CVE-2017-16661?
Attackers can exploit CVE-2017-16661 to read arbitrary files on the server, potentially compromising sensitive data.