#VU9571 OS command injection in Cacti - CVE-2017-16641
Published: December 7, 2017
Cacti
The Cacti Group, Inc.
Description
The vulnerability allows a remote high-privileged attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to an error in lib/rrd.php. A remote attacker can place the Log Path under the web root, make a specially crafted specially crafted action=save request containing the 'path_rrdtool' parameter to settings.php and execute arbitrary shell commands with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.