Information disclosure in Cacti - CVE-2017-16661
Published: December 2, 2017 / Updated: December 7, 2017
Cacti
Detailed vulnerability description
The vulnerability allows a remote high-privileged attacker to obtain potentially sensitive information.
The vulnerability exists due to improper validation of user-supplied requests. A remote attacker can place the Log Path into a private directory, make a specially crafted clog.php?filename= request and read /etc/passwd.