Skip to main content

Vendor/product archive

the_cacti_group / cacti CVEs

Beta · best-effort

15 CVEs tagged to the_cacti_group / cacti2 Critical, 9 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2007-3112

Published Jun 7, 2007

graph_image.php in Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_s…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3113

Published Jun 7, 2007

Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_height or (2) graph_…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6799

Published Dec 28, 2006

SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL commands via the (1) second or (2) th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2148

Published Jul 6, 2005

Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitrary commands or SQL by sending…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2149

Published Jul 6, 2005

config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslas…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-1524

Published Jun 22, 2005

PHP file inclusion vulnerability in top_graph_header.php in Cacti 0.8.6d and possibly earlier versions allows remote attackers to execute arbitrary PHP code via the config[library…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1525

Published Jun 22, 2005

SQL injection vulnerability in config_settings.php for Cacti before 0.8.6e allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1526

Published Jun 22, 2005

PHP remote file inclusion vulnerability in config_settings.php in Cacti before 0.8.6e allows remote attackers to execute arbitrary PHP code via the config[include_path] parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1736

Published Dec 31, 2004

Cacti 0.8.5a allows remote attackers to gain sensitive information via an HTTP request to (1) auth.php, (2) auth_login.php, (3) auth_changepassword.php, and possibly other php fil…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1737

Published Aug 16, 2004

SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) passw…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1477

Published Apr 22, 2003

graphs.php in Cacti before 0.6.8 allows remote authenticated Cacti administrators to execute arbitrary commands via shell metacharacters in the title during edit mode.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1478

Published Apr 22, 2003

Cacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-1479

Published Apr 22, 2003

Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users to modify databases as the Cacti…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1