High severity8.8NVD Advisory· Published Jan 11, 2021· Updated Jun 17, 2026
CVE-2020-35701
CVE-2020-35701
Description
An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in data_debug.php allows remote authenticated attackers to execute arbitrary SQL commands via the site_id parameter. This can lead to remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13- Cacti/Cactidescription
- osv-coords7 versionspkg:rpm/opensuse/cacti&distro=openSUSE%20Tumbleweedpkg:rpm/suse/cacti&distro=SUSE%20Package%20Hub%2012pkg:rpm/opensuse/cacti-spine&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/cacti&distro=SUSE%20Package%20Hub%2015%20SP2pkg:rpm/suse/cacti-spine&distro=SUSE%20Package%20Hub%2015%20SP2pkg:rpm/suse/cacti-spine&distro=SUSE%20Package%20Hub%2012pkg:rpm/opensuse/cacti&distro=openSUSE%20Leap%2015.2
< 1.2.18-1.2+ 6 more
- (no CPE)range: < 1.2.18-1.2
- (no CPE)range: < 1.2.17-20.1
- (no CPE)range: < 1.2.17-14.1
- (no CPE)range: < 1.2.17-bp152.2.10.1
- (no CPE)range: < 1.2.17-bp152.2.7.1
- (no CPE)range: < 1.2.17-14.1
- (no CPE)range: < 1.2.17-20.1
1.2.x through 1.2.16+ 1 more
- (no CPE)range: 1.2.x through 1.2.16
- cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*range: >=1.2.0,<=1.2.16
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- asaf.me/2020/12/15/cacti-1-2-0-to-1-2-16-sql-injection/nvdExploitThird Party Advisory
- github.com/Cacti/cacti/issues/4022nvdThird Party Advisory
- security.gentoo.org/glsa/202101-31nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6DDD22Z56THHDTXAFM447UH3BVINURIF/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C7DPUWZBAMCXFKAKUAJSHL3CKTOLGAK6/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NBKBR2MFZJ6C2I4I5PCRR6UERPY24XZN/nvd
News mentions
0No linked articles in our index yet.