Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Cacti
(The_cacti_group)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 15 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2003-04-22 | CVE-2002-1479 | Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users to modify databases as the Cacti user and possibly gain privileges. | Cacti | N/A | ||
2003-04-22 | CVE-2002-1478 | Cacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode. | Cacti | N/A | ||
2003-04-22 | CVE-2002-1477 | graphs.php in Cacti before 0.6.8 allows remote authenticated Cacti administrators to execute arbitrary commands via shell metacharacters in the title during edit mode. | Cacti | N/A | ||
2006-01-09 | CVE-2006-0146 | The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter. | Adodb, Mantis, Mediabeez, Moodle, Postnuke, Cacti | N/A | ||
2007-06-07 | CVE-2007-3113 | Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_height or (2) graph_width parameter, different vectors than CVE-2007-3112. | Cacti | N/A |