Rapid7
BACK TO VEDB

CVE-2017-6188: Improper Input Validation

REQUEST DEMO

Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www-data user.

CVSS Details

  • CVSS 3.1 Base Score: 5.5
  • CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)

Covered by Rapid7

ProductVendor AdvisorySolution FileAddedPublished
Alpine Linux
View advisory ↗View advisory ↗
alpine-linux-upgrade-munin
Aug 30, 2017Feb 22, 2017
Amazon_linux—
amazon-linux-upgrade-munin
Apr 20, 2017Feb 22, 2017
Arch Linux
View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗View advisory ↗
arch-linux-upgrade-latest
Jul 11, 2025Feb 22, 2017
Debian
View advisory ↗
debian-upgrade-munin
Feb 27, 2017Feb 22, 2017
Gentoo Linux
View advisory ↗
gentoo-linux-upgrade-net-analyzer-munin
Oct 30, 2017Feb 22, 2017
Suse—
suse-upgrade-muninsuse-upgrade-munin-node
Mar 7, 2017Feb 22, 2017
Ubuntu
View advisory ↗
ubuntu-upgrade-munin
Mar 3, 2017Feb 22, 2017

Prioritise with Active Threat Intelligence

With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.

Explore Intelligence Hub

CVE details

CVSS v4 ScoreN/A
CVSS v3 Score5.5 Medium
EPSS Score0%
EPSS Percentile35%
In CISA KEV CatalogueFalse

Published

Feb 22, 2017

References

  • NVD ↗
    Rapid7
    Request Demo
    • Request Demo
    • Explore platform
    • Exposure Management
    • Attack Surface Management
    • Vulnerability Management
    • Cloud-Native Application Protection
    • Application Security
    • Next-Gen SIEM
    • Threat Intelligence Platform
    • Start a Free Trial
    • AI-Engine
    • Rapid7 Labs
    • Self-Guided Platform Tour
    • Talk to an Expert
    • Rapid7 Threat Intelligence
    • All Products
    • Managed Detection and Response
    • MDR for Microsoft
    • MDR for Enterprise
    • Incident Response Services
    • Rapid7 vs. Them
    • Customer Stories
    • MDR Product Tour
    • MDR ROI Calculator
    • Managed Vulnerability Management
    • Continuous Red Teaming
    • Managed Application Security
    • Penetration Testing Services
    • All services
    • READ NOW
    • Rapid7 Labs
    • Emergent Threat Response
    • Vulnerability & Exploit Database
    • Blog
    • Webinars and Events
    • Resource Library
    • Cybersecurity Fundamentals
    • Product Documentation
    • Product Release Notes
    • Product Extensions
    • Product Toolkits
    • Customer Support
    • Rapid7 Forum
    • Partnerships Overview
    • PACT Partner Program
    • PACT for Service Providers
    • Partner Directory
    • Technology Partners
    • AWS Partnership
    • Partner Login
    • Become a Partner
    • Become a partner
    • About Us
    • Leadership Team
    • Our Customers
    • Careers
    • Contact Us
    • Newsroom
    • Awards and Recognition
    • Investors
    • Social Good
    • Culture
    • Boston Bruins Partnership
    • Book live demo
    Rapid7

    Get Started

    Command Platform
    Exposure Management
    MDR Services
    Solutions

    Take Action

    Start a Free Trial
    Take a Product Tour
    Get Breach Support
    Contact Sales

    Company

    • About Us
    • Leadership
    • Newsroom
    • Our Customers
    • Partner Programs
    • Investors
    • Careers

    Stay Informed

    • Blog
    • Emergent Threat Response
    • Webinars & Events
    • Rapid7 Labs Research
    • Vulnerability Database
    • Security Fundamentals

    For Customers

    • Sign In
    • Support Portal
    • Product Documentation
    • Extension Library
    • Rapid7 Academy
    • Customer Escalation Portal

    Contact Support

    • +1-866-390-8113

    Follow Us

    LinkedIn icon
    LinkedIn
    X (Twitter) icon
    X (Twitter)
    Facebook icon
    Facebook
    Instagram icon
    Instagram
    Bluesky icon
    Bluesky
    © Rapid7
    Legal TermsPrivacy PolicyExport NoticeTrustCookie ListAccessibility Statement