lib/rrd.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified parameters.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 1 | cacti | 2014-06-03 14:59 | ALAS-2014-347 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv2 | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P |
NVD | CVSSv2 | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P |