CVE-2017-16660 log

Severity High
Remote Yes
Type Arbitrary code execution
Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path under the web root, and then making a remote_agent.php request containing PHP code in a Client-ip header.
Group Package Affected Fixed Severity Status Ticket
AVG-537 cacti 1.1.17-1 1.1.28-1 High Fixed
Date Advisory Group Package Severity Type
02 Dec 2017 ASA-201712-2 AVG-537 cacti High multiple issues