CVE-2016-10700

Published: Nov 24, 2017 Last Modified: Apr 20, 2025 EU-VD ID: EUVD-2016-1701 Aliases: GSD-2016-10700
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 8,8
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
MEDIUM 6,5
Access Vector: network
Access Complexity: low
Authentication: single
Confidentiality: partial
Integrity: partial
Availability: partial

Description

AI Translation Available

auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database, because the guest user is not considered. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-2313.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0055
Percentile
0,7th
Updated

EPSS Score Trend (Last 91 Days)

Application

Cacti by Cacti

Version Range Affected
To 1.0.0 (exclusive)
cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
http://bugs.cacti.net/view.php?id=2697
https://github.com/Cacti/cacti/commit/69983495cd41bf0903fe02baeef84b1fa85f2846
https://web.archive.org/web/20160817090458/http://bugs.cacti.net/view.php?id=26…
http://www.cacti.net/release_notes_1_0_0.php
Issue Tracking Release Notes Vendor Advisory
http://www.cacti.net/release_notes_1_0_0.php
http://bugs.cacti.net/view.php?id=2697
https://github.com/Cacti/cacti/commit/69983495cd41bf0903fe02baeef84b1fa85f2846
https://web.archive.org/web/20160817090458/http://bugs.cacti.net/view.php?id=26…
http://www.cacti.net/release_notes_1_0_0.php
Issue Tracking Release Notes Vendor Advisory
http://www.cacti.net/release_notes_1_0_0.php