CVE-2005-2148
published 2005-07-06CVE-2005-2148: Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitrary…
PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.40%
87.6th percentile
Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitrary commands or SQL by sending a legitimate value in a POST request or cookie, then specifying the attack string in the URL, which causes the get_request_var function to return the wrong value in the $_REQUEST variable, which is cleansed while the original malicious $_GET value remains unmodified, as demonstrated in (1) graph_image.php and (2) graph.php.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cacti | cacti | >= 0 < 0.8.6f-1 | 0.8.6f-1 |
| cacti | cacti | >= 0 < 0.8.6f-1 | 0.8.6f-1 |
| cacti | cacti | >= 0 < 0.8.6f-1 | 0.8.6f-1 |
| cacti | cacti | >= 0 < 0.8.6f-1 | 0.8.6f-1 |
| debian | cacti | < cacti 0.8.6f-1 (bookworm) | cacti 0.8.6f-1 (bookworm) |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
| the_cacti_group | cacti | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2005-2148: cacti - Cacti 0.8.6e and earlier does not perform proper input validation to protect aga...
vendor_debian·2005·CVSS 7.5
CVE-2005-2148 [HIGH] CVE-2005-2148: cacti - Cacti 0.8.6e and earlier does not perform proper input validation to protect aga...
Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitrary commands or SQL by sending a legitimate value in a POST request or cookie, then specifying the attack string in the URL, which causes the get_request_var function to return the wrong value in the $_REQUEST variable, which is cleansed while the original malicious $_GET value remains unmodified, as demonstrated in (1) graph_image.php and (2) graph.php.
Scope: local
bookworm: resolved (fixed in 0.8.6f-1)
bullseye: resolved (fixed in 0.8.6f-1)
forky: resolved (fixed in 0.8.6f-1)
sid: resolved (fixed in 0.8.6f-1)
trixie: resolved (fixed in 0.8.6f-1)
GHSA
GHSA-cqpx-grv2-8p3h: Cacti 0
ghsa_unreviewed·2022-05-01
CVE-2005-2148 [HIGH] GHSA-cqpx-grv2-8p3h: Cacti 0
Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitrary commands or SQL by sending a legitimate value in a POST request or cookie, then specifying the attack string in the URL, which causes the get_request_var function to return the wrong value in the $_REQUEST variable, which is cleansed while the original malicious $_GET value remains unmodified, as demonstrated in (1) graph_image.php and (2) graph.php.
OSV
CVE-2005-2148: Cacti 0
osv·2005-07-06·CVSS 7.5
CVE-2005-2148 [HIGH] CVE-2005-2148: Cacti 0
Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitrary commands or SQL by sending a legitimate value in a POST request or cookie, then specifying the attack string in the URL, which causes the get_request_var function to return the wrong value in the $_REQUEST variable, which is cleansed while the original malicious $_GET value remains unmodified, as demonstrated in (1) graph_image.php and (2) graph.php.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/15490http://securitytracker.com/id?1014361http://sourceforge.net/mailarchive/forum.php?forum_id=10360&max_rows=25&style=flat&viewmonth=200507&viewday=1http://www.cacti.net/downloads/patches/0.8.6e/cacti-0.8.6f_security.patchhttp://www.debian.org/security/2005/dsa-764http://www.hardened-php.net/advisory-032005.phphttp://www.hardened-php.net/advisory-042005.phphttp://www.securityfocus.com/archive/1/404047/30/30/threadedhttp://www.securityfocus.com/archive/1/404054http://www.securityfocus.com/bid/14128http://www.securityfocus.com/bid/14129http://www.vupen.com/english/advisories/2005/0951https://exchange.xforce.ibmcloud.com/vulnerabilities/21266https://exchange.xforce.ibmcloud.com/vulnerabilities/21270http://secunia.com/advisories/15490http://securitytracker.com/id?1014361http://sourceforge.net/mailarchive/forum.php?forum_id=10360&max_rows=25&style=flat&viewmonth=200507&viewday=1http://www.cacti.net/downloads/patches/0.8.6e/cacti-0.8.6f_security.patchhttp://www.debian.org/security/2005/dsa-764http://www.hardened-php.net/advisory-032005.phphttp://www.hardened-php.net/advisory-042005.phphttp://www.securityfocus.com/archive/1/404047/30/30/threadedhttp://www.securityfocus.com/archive/1/404054http://www.securityfocus.com/bid/14128http://www.securityfocus.com/bid/14129http://www.vupen.com/english/advisories/2005/0951https://exchange.xforce.ibmcloud.com/vulnerabilities/21266https://exchange.xforce.ibmcloud.com/vulnerabilities/21270
2005-07-06
Published