VYPR

Cacti

by Cacti (software)

Source repositories

CVEs (171)

  • CVE-2023-39357HigSep 5, 2023
    risk 0.57cvss 8.8epss 0.02

    Cacti is an open source operational monitoring and fault management framework. A defect in the sql_save function was discovered. When the column type is numeric, the sql_save function directly utilizes user input. Many files and functions calling the sql_save function do not…

  • CVE-2023-39359HigSep 5, 2023
    risk 0.57cvss 8.8epss 0.02

    Cacti is an open source operational monitoring and fault management framework. An authenticated SQL injection vulnerability was discovered which allows authenticated users to perform privilege escalation and remote code execution. The vulnerability resides in the `graphs.php`…

  • CVE-2020-14295HigJun 17, 2020
    risk 0.57cvss 7.2epss 0.86

    A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries.

  • CVE-2020-7058HigJan 15, 2020
    risk 0.57cvss 8.8epss 0.02

    data_input.php in Cacti 1.2.8 allows remote code execution via a crafted Input String to Data Collection -> Data Input Methods -> Unix -> Ping Host. NOTE: the vendor has stated "This is a false alarm.

  • CVE-2014-4000HigNov 15, 2017
    risk 0.57cvss 8.8epss 0.02

    Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object, related to calling unserialize(stripslashes()).

  • CVE-2017-1000031HigJul 17, 2017
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary SQL commands via the graph_template_input_id and graph_template_id parameters.

  • CVE-2016-2313HigApr 13, 2016
    risk 0.57cvss 8.8epss 0.03

    auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.

  • CVE-2016-3172HigApr 12, 2016
    risk 0.57cvss 8.8epss 0.03

    SQL injection vulnerability in tree.php in Cacti 0.8.8g and earlier allows remote authenticated users to execute arbitrary SQL commands via the parent_id parameter in an item_edit action.

  • CVE-2015-8604HigApr 11, 2016
    risk 0.57cvss 8.8epss 0.02

    SQL injection vulnerability in the host_new_graphs function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via the cg_g parameter in a save action.

  • CVE-2016-3659HigApr 11, 2016
    risk 0.57cvss 8.8epss 0.02

    SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote authenticated users to execute arbitrary SQL commands via the host_group_data parameter.

  • CVE-2023-39362HigSep 5, 2023
    risk 0.56cvss 7.2epss 0.82

    Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, under certain conditions, an authenticated privileged user, can use a malicious string in the SNMP options of a Device, performing command injection and obtaining remote code…

  • CVE-2024-31459HigMay 14, 2024
    risk 0.52cvss 8.0epss 0.03

    Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, there is a file inclusion issue in the `lib/plugin.php` file. Combined with SQL injection vulnerabilities, remote code execution can be implemented. There is a file inclusion issue…

  • CVE-2023-31132HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a privilege escalation vulnerability. A low-privileged OS user with access to a Windows host where Cacti is installed can create arbitrary PHP files in a web document…

  • CVE-2024-43363HigOct 7, 2024
    risk 0.50cvss 7.2epss 0.36

    Cacti is an open source performance and fault management framework. An admin user can create a device with a malicious hostname containing php code and repeat the installation process (completing only step 5 of the installation process is enough, no need to complete the steps…

  • CVE-2024-43362HigOct 7, 2024
    risk 0.50cvss 7.3epss 0.35

    Cacti is an open source performance and fault management framework. The `fileurl` parameter is not properly sanitized when saving external links in `links.php` . Morever, the said fileurl is placed in some html code which is passed to the `print` function in `link.php` and…

  • CVE-2016-10700HigNov 24, 2017
    risk 0.50cvss 8.8epss 0.02

    auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database, because the guest user is not considered. NOTE: this vulnerability exists because of an…

  • CVE-2024-27082HigMay 14, 2024
    risk 0.49cvss 7.6epss 0.01

    Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 are vulnerable to stored cross-site scripting, a type of cross-site scripting where malicious scripts are permanently stored on a target server and served to users who…

  • CVE-2023-37543HigAug 10, 2023
    risk 0.49cvss 7.5epss 0.01

    Cacti before 1.2.6 allows IDOR (Insecure Direct Object Reference) for accessing any graph via a modified local_graph_id parameter to graph_xport.php. This is a different vulnerability than CVE-2019-16723.

  • CVE-2017-16660HigNov 8, 2017
    risk 0.47cvss 7.2epss 0.04

    Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path under the web root, and then making a remote_agent.php request containing PHP code in a Client-ip header.

  • CVE-2017-16641HigNov 7, 2017
    risk 0.47cvss 7.2epss 0.03

    lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execute arbitrary OS commands via the path_rrdtool parameter in an action=save request to settings.php.

Page 2 of 9