Vulnerabilities
Vulnerable Software
The Cacti Group:  >> Cacti  Security Vulnerabilities
Cacti 0.8.5a allows remote attackers to gain sensitive information via an HTTP request to (1) auth.php, (2) auth_login.php, (3) auth_changepassword.php, and possibly other php files, which reveal the installation path in a PHP error message.
CVSS Score
5.0
EPSS Score
0.005
Published
2004-12-31
SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters.
CVSS Score
7.5
EPSS Score
0.038
Published
2004-08-16
graphs.php in Cacti before 0.6.8 allows remote authenticated Cacti administrators to execute arbitrary commands via shell metacharacters in the title during edit mode.
CVSS Score
7.5
EPSS Score
0.027
Published
2003-04-22
Cacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode.
CVSS Score
10.0
EPSS Score
0.009
Published
2003-04-22
Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users to modify databases as the Cacti user and possibly gain privileges.
CVSS Score
4.6
EPSS Score
0.001
Published
2003-04-22


Contact Us

Shodan ® - All rights reserved