CVE-2005-1525

6 documents6 sources
Severity
7.5HIGH
EPSS
1.6%
top 18.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 22
Latest updateMay 1

Description

SQL injection vulnerability in config_settings.php for Cacti before 0.8.6e allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

Debiancacti< 0.8.6e-1+3
NVDthe_cacti_group/cacti0.8.6d+19

Patches

🔴Vulnerability Details

3
GHSA
GHSA-g8cm-8qmx-72v9: SQL injection vulnerability in config_settings2022-05-01
CVEList
CVE-2005-1525: SQL injection vulnerability in config_settings2005-06-22
OSV
CVE-2005-1525: SQL injection vulnerability in config_settings2005-06-22

📋Vendor Advisories

1
Debian
CVE-2005-1525: cacti - SQL injection vulnerability in config_settings.php for Cacti before 0.8.6e allow...2005
CVE-2005-1525 (HIGH CVSS 7.5) | SQL injection vulnerability in conf | cvebase.io