Unrated severityNVD Advisory· Published Apr 23, 2014· Updated May 6, 2026
CVE-2014-2327
CVE-2014-2327
Description
Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users for unspecified commands, as demonstrated by requests that (1) modify binary files, (2) modify configurations, or (3) add arbitrary users.
Affected products
5cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- jvn.jp/en/jp/JVN55076671/index.htmlnvdThird Party AdvisoryVDB Entry
- jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-002239.htmlnvdThird Party AdvisoryVDB Entry
- lists.opensuse.org/opensuse-updates/2015-03/msg00034.htmlnvdThird Party Advisory
- secunia.com/advisories/59203nvdThird Party Advisory
- www.debian.org/security/2014/dsa-2970nvdThird Party Advisory
- www.securityfocus.com/archive/1/531588nvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/66392nvdThird Party AdvisoryVDB Entry
- bugs.debian.org/cgi-bin/bugreport.cginvdIssue TrackingThird Party Advisory
- security.gentoo.org/glsa/201509-03nvdThird Party Advisory
News mentions
0No linked articles in our index yet.