Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
the cacti group cacti 0.6.7 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2002-1477
graphs.php in Cacti prior to 0.6.8 allows remote authenticated Cacti administrators to execute arbitrary commands via shell metacharacters in the title during edit mode.
The Cacti Group Cacti 0.5
The Cacti Group Cacti 0.6.7
The Cacti Group Cacti 0.6.4
The Cacti Group Cacti 0.6.1
The Cacti Group Cacti 0.6
The Cacti Group Cacti 0.6.6
The Cacti Group Cacti 0.6.5
The Cacti Group Cacti 0.6.3
The Cacti Group Cacti 0.6.8
The Cacti Group Cacti 0.6.2
NA
CVE-2002-1479
Cacti prior to 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users to modify databases as the Cacti user and possibly gain privileges.
The Cacti Group Cacti 0.5
The Cacti Group Cacti 0.6.7
The Cacti Group Cacti 0.6.4
The Cacti Group Cacti 0.6.1
The Cacti Group Cacti 0.6
The Cacti Group Cacti 0.6.6
The Cacti Group Cacti 0.6.5
The Cacti Group Cacti 0.6.3
The Cacti Group Cacti 0.6.8
The Cacti Group Cacti 0.6.2
NA
CVE-2002-1478
Cacti prior to 0.6.8 allows malicious users to execute arbitrary commands via the "Data Input" option in console mode.
The Cacti Group Cacti 0.5
The Cacti Group Cacti 0.6.7
The Cacti Group Cacti 0.6.4
The Cacti Group Cacti 0.6.1
The Cacti Group Cacti 0.6
The Cacti Group Cacti 0.6.6
The Cacti Group Cacti 0.6.5
The Cacti Group Cacti 0.6.3
The Cacti Group Cacti 0.6.8
The Cacti Group Cacti 0.6.2
NA
CVE-2005-1524
PHP file inclusion vulnerability in top_graph_header.php in Cacti 0.8.6d and possibly earlier versions allows remote malicious users to execute arbitrary PHP code via the config[library_path] parameter.
The Cacti Group Cacti 0.5
The Cacti Group Cacti 0.6.7
The Cacti Group Cacti 0.8.2a
The Cacti Group Cacti 0.6.4
The Cacti Group Cacti 0.6.1
The Cacti Group Cacti 0.6
The Cacti Group Cacti 0.8.3a
The Cacti Group Cacti 0.8
The Cacti Group Cacti 0.6.6
The Cacti Group Cacti
The Cacti Group Cacti 0.6.5
The Cacti Group Cacti 0.8.5a
The Cacti Group Cacti 0.8.4
The Cacti Group Cacti 0.8.3
The Cacti Group Cacti 0.8.1
The Cacti Group Cacti 0.8.2
The Cacti Group Cacti 0.6.3
The Cacti Group Cacti 0.6.8
The Cacti Group Cacti 0.6.8a
The Cacti Group Cacti 0.6.2
2 EDB exploits
NA
CVE-2005-1526
PHP remote file inclusion vulnerability in config_settings.php in Cacti prior to 0.8.6e allows remote malicious users to execute arbitrary PHP code via the config[include_path] parameter.
The Cacti Group Cacti 0.5
The Cacti Group Cacti 0.6.7
The Cacti Group Cacti 0.8.2a
The Cacti Group Cacti 0.6.4
The Cacti Group Cacti 0.6.1
The Cacti Group Cacti 0.6
The Cacti Group Cacti 0.8.3a
The Cacti Group Cacti 0.8
The Cacti Group Cacti 0.6.6
The Cacti Group Cacti
The Cacti Group Cacti 0.6.5
The Cacti Group Cacti 0.8.5a
The Cacti Group Cacti 0.8.4
The Cacti Group Cacti 0.8.3
The Cacti Group Cacti 0.8.1
The Cacti Group Cacti 0.8.2
The Cacti Group Cacti 0.6.3
The Cacti Group Cacti 0.6.8
The Cacti Group Cacti 0.6.8a
The Cacti Group Cacti 0.6.2
1 EDB exploit
NA
CVE-2005-1525
SQL injection vulnerability in config_settings.php for Cacti prior to 0.8.6e allows remote malicious users to execute arbitrary SQL commands via the id parameter.
The Cacti Group Cacti 0.5
The Cacti Group Cacti 0.6.7
The Cacti Group Cacti 0.8.2a
The Cacti Group Cacti 0.6.4
The Cacti Group Cacti 0.6.1
The Cacti Group Cacti 0.6
The Cacti Group Cacti 0.8.3a
The Cacti Group Cacti 0.8
The Cacti Group Cacti 0.6.6
The Cacti Group Cacti
The Cacti Group Cacti 0.6.5
The Cacti Group Cacti 0.8.5a
The Cacti Group Cacti 0.8.4
The Cacti Group Cacti 0.8.3
The Cacti Group Cacti 0.8.1
The Cacti Group Cacti 0.8.2
The Cacti Group Cacti 0.6.3
The Cacti Group Cacti 0.6.8
The Cacti Group Cacti 0.6.8a
The Cacti Group Cacti 0.6.2
NA
CVE-2004-1737
SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote malicious users to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters.
The Cacti Group Cacti 0.8.5
The Cacti Group Cacti 0.6.7
The Cacti Group Cacti 0.8.2a
The Cacti Group Cacti 0.6.4
The Cacti Group Cacti 0.6.1
The Cacti Group Cacti 0.6
The Cacti Group Cacti 0.8.3a
The Cacti Group Cacti 0.8
The Cacti Group Cacti 0.6.6
The Cacti Group Cacti 0.6.5
The Cacti Group Cacti 0.8.5a
The Cacti Group Cacti 0.8.4
The Cacti Group Cacti 0.8.3
The Cacti Group Cacti 0.8.1
The Cacti Group Cacti 0.8.2
The Cacti Group Cacti 0.6.3
The Cacti Group Cacti 0.6.8
The Cacti Group Cacti 0.6.8a
The Cacti Group Cacti 0.6.2
Gentoo Linux 1.4
1 EDB exploit
NA
CVE-2005-2149
config.php in Cacti 0.8.6e and previous versions allows remote malicious users to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.
The Cacti Group Cacti 0.8.5
The Cacti Group Cacti 0.8.6b
The Cacti Group Cacti 0.8.6c
The Cacti Group Cacti 0.8.6a
The Cacti Group Cacti 0.8.2a
The Cacti Group Cacti 0.8.3a
The Cacti Group Cacti 0.8
The Cacti Group Cacti 0.8.5a
The Cacti Group Cacti 0.8.4
The Cacti Group Cacti 0.8.6
The Cacti Group Cacti 0.8.3
The Cacti Group Cacti 0.8.1
The Cacti Group Cacti 0.8.2
The Cacti Group Cacti 0.8.6d
The Cacti Group Cacti 0.8.6e
NA
CVE-2005-2148
Cacti 0.8.6e and previous versions does not perform proper input validation to protect against common attacks, which allows remote malicious users to execute arbitrary commands or SQL by sending a legitimate value in a POST request or cookie, then specifying the attack string in ...
The Cacti Group Cacti 0.8.5
The Cacti Group Cacti 0.8.6b
The Cacti Group Cacti 0.8.6c
The Cacti Group Cacti 0.8.6a
The Cacti Group Cacti 0.8.2a
The Cacti Group Cacti 0.8.3a
The Cacti Group Cacti 0.8
The Cacti Group Cacti 0.8.5a
The Cacti Group Cacti 0.8.4
The Cacti Group Cacti 0.8.6
The Cacti Group Cacti 0.8.3
The Cacti Group Cacti 0.8.1
The Cacti Group Cacti 0.8.2
The Cacti Group Cacti 0.8.6d
The Cacti Group Cacti 0.8.6e
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started