CVE-2017-16785: XSS
Published Nov 10, 2017
·Updated
Cacti 1.1.27 has reflected XSS via the PATHINFO to host.php.
Affected Software
1 affected component
Cacti Cacti=1.1.27
Remediation
Patch Available
Event History
Nov 10, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-16785?
CVE-2017-16785 has a medium severity due to its potential for reflected XSS attacks.
2
How do I fix CVE-2017-16785?
To mitigate CVE-2017-16785, upgrade Cacti to version 1.1.28 or later.
3
What systems are affected by CVE-2017-16785?
CVE-2017-16785 affects Cacti version 1.1.27.
4
Can CVE-2017-16785 be exploited remotely?
Yes, CVE-2017-16785 can be exploited remotely through a specially crafted request.
5
What type of attack does CVE-2017-16785 enable?
CVE-2017-16785 enables reflected Cross-Site Scripting (XSS) attacks.