10
CVSSv2

CVE-2005-2149

Published: 06/07/2005 Updated: 08/03/2011
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

config.php in Cacti 0.8.6e and previous versions allows remote malicious users to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.

Vulnerable Product Search on Vulmon Subscribe to Product

the cacti group cacti 0.8.2

the cacti group cacti 0.8.2a

the cacti group cacti 0.8.6a

the cacti group cacti 0.8.6b

the cacti group cacti 0.8.4

the cacti group cacti 0.8.5

the cacti group cacti 0.8.6e

the cacti group cacti 0.8.3

the cacti group cacti 0.8.3a

the cacti group cacti 0.8.6c

the cacti group cacti 0.8.6d

the cacti group cacti 0.8

the cacti group cacti 0.8.1

the cacti group cacti 0.8.5a

the cacti group cacti 0.8.6

Vendor Advisories

Several vulnerabilities have been discovered in cacti, a round-robin database (RRD) tool that helps create graphs from database information The Common Vulnerabilities and Exposures Project identifies the following problems: CAN-2005-1524 Maciej Piotr Falkiewicz and an anonymous researcher discovered an input validation bug that allows an ...