CVE-2017-16660: Cacti
High severity, CVSS 7.2. EPSS: 4.2% chance of exploitation in the next 30 days.
Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path under the web root, and then making a remote_agent.php request containing PHP code in a Client-ip header.
Affected products
- Cacti Cacti: version 1.1.27 only
Published 2017-11-08. Last modified 2026-06-17.