CVE-2014-2327

high

Description

Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users for unspecified commands, as demonstrated by requests that (1) modify binary files, (2) modify configurations, or (3) add arbitrary users.

References

https://security.gentoo.org/glsa/201509-03

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742768

http://www.securityfocus.com/bid/66392

http://www.securityfocus.com/archive/1/531588

http://www.debian.org/security/2014/dsa-2970

http://secunia.com/advisories/59203

http://lists.opensuse.org/opensuse-updates/2015-03/msg00034.html

http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-002239.html

http://jvn.jp/en/jp/JVN55076671/index.html

Details

Source: Mitre, NVD

Published: 2014-04-23

Updated: 2018-12-13

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High