High severity8.8NVD Advisory· Published Nov 15, 2017· Updated May 13, 2026
CVE-2014-4000
CVE-2014-4000
Description
Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object, related to calling unserialize(stripslashes()).
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- forums.cacti.net/viewtopic.phpnvdIssue TrackingRelease NotesVendor Advisory
- security-tracker.debian.org/tracker/CVE-2014-4000nvdIssue TrackingThird Party Advisory
- security.gentoo.org/glsa/201711-10nvdIssue TrackingThird Party Advisory
- www.cacti.net/release_notes_1_0_0.phpnvdIssue TrackingRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.