4.6
CVSSv2

CVE-2002-1479

Published: 22/04/2003 Updated: 14/02/2024
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cacti prior to 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users to modify databases as the Cacti user and possibly gain privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

the cacti group cacti 0.5

the cacti group cacti 0.6.7

the cacti group cacti 0.6.4

the cacti group cacti 0.6.1

the cacti group cacti 0.6

the cacti group cacti 0.6.6

the cacti group cacti 0.6.5

the cacti group cacti 0.6.3

the cacti group cacti 0.6.8

the cacti group cacti 0.6.2