CVE-2006-6799
published 2006-12-28CVE-2006-6799: SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL commands via the…
PriorityP339high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.52%
83.2th percentile
SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL commands via the (1) second or (2) third arguments to cmd.php. NOTE: this issue can be leveraged to execute arbitrary commands since the SQL query results are later used in the polling_items array and popen function.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cacti | cacti | >= 0 < 0.8.6i-3 | 0.8.6i-3 |
| cacti | cacti | >= 0 < 0.8.6i-3 | 0.8.6i-3 |
| cacti | cacti | >= 0 < 0.8.6i-3 | 0.8.6i-3 |
| cacti | cacti | >= 0 < 0.8.6i-3 | 0.8.6i-3 |
| debian | cacti | < cacti 0.8.6i-3 (bookworm) | cacti 0.8.6i-3 (bookworm) |
| the_cacti_group | cacti | <= 0.8.6i | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8f93-437m-m53h: SQL injection vulnerability in Cacti 0
ghsa_unreviewed·2022-05-01
CVE-2006-6799 [HIGH] GHSA-8f93-437m-m53h: SQL injection vulnerability in Cacti 0
SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL commands via the (1) second or (2) third arguments to cmd.php. NOTE: this issue can be leveraged to execute arbitrary commands since the SQL query results are later used in the polling_items array and popen function.
OSV
CVE-2006-6799: SQL injection vulnerability in Cacti 0
osv·2006-12-28·CVSS 7.5
CVE-2006-6799 [HIGH] CVE-2006-6799: SQL injection vulnerability in Cacti 0
SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL commands via the (1) second or (2) third arguments to cmd.php. NOTE: this issue can be leveraged to execute arbitrary commands since the SQL query results are later used in the polling_items array and popen function.
Debian
CVE-2006-6799: cacti - SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv...
vendor_debian·2006·CVSS 7.5
CVE-2006-6799 [HIGH] CVE-2006-6799: cacti - SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv...
SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL commands via the (1) second or (2) third arguments to cmd.php. NOTE: this issue can be leveraged to execute arbitrary commands since the SQL query results are later used in the polling_items array and popen function.
Scope: local
bookworm: resolved (fixed in 0.8.6i-3)
bullseye: resolved (fixed in 0.8.6i-3)
forky: resolved (fixed in 0.8.6i-3)
sid: resolved (fixed in 0.8.6i-3)
trixie: resolved (fixed in 0.8.6i-3)
No detection rules found.
No public exploits indexed.
CAPEC
Command Line Execution through SQL Injection
mitre_capec
[CRITICAL] Command Line Execution through SQL Injection
CAPEC-108: Command Line Execution through SQL Injection
An attacker uses standard SQL injection methods to inject data into the command line for execution. This could be done directly through misuse of directives such as MSSQL_xp_cmdshell or indirectly through injection of data into the database that would be interpreted as shell commands. Sometime later, an unscrupulous backend application (or could be part of the functionality of the same application) fetches the injected data stored in the database and uses this data as command line arguments without performing proper validation. The malicious data escapes that data plane by spawning new commands to be executed on the host.
Execution Flow:
Step 1 [Explore]: [Probe for SQL Injection vulnerability] The attacker injects SQL syntax into u
http://secunia.com/advisories/23528http://secunia.com/advisories/23665http://secunia.com/advisories/23917http://secunia.com/advisories/23941http://security.gentoo.org/glsa/glsa-200701-23.xmlhttp://securitytracker.com/id?1017451http://www.cacti.net/release_notes_0_8_6j.phphttp://www.debian.org/security/2007/dsa-1250http://www.mandriva.com/security/advisories?name=MDKSA-2007:015http://www.novell.com/linux/security/advisories/2007_07_cacti.htmlhttp://www.openpkg.com/security/advisories/OpenPKG-SA-2007.001.htmlhttp://www.securityfocus.com/archive/1/457290/100/0/threadedhttp://www.securityfocus.com/bid/21799http://www.vupen.com/english/advisories/2006/5193https://exchange.xforce.ibmcloud.com/vulnerabilities/31177https://www.exploit-db.com/exploits/3029http://secunia.com/advisories/23528http://secunia.com/advisories/23665http://secunia.com/advisories/23917http://secunia.com/advisories/23941http://security.gentoo.org/glsa/glsa-200701-23.xmlhttp://securitytracker.com/id?1017451http://www.cacti.net/release_notes_0_8_6j.phphttp://www.debian.org/security/2007/dsa-1250http://www.mandriva.com/security/advisories?name=MDKSA-2007:015http://www.novell.com/linux/security/advisories/2007_07_cacti.htmlhttp://www.openpkg.com/security/advisories/OpenPKG-SA-2007.001.htmlhttp://www.securityfocus.com/archive/1/457290/100/0/threadedhttp://www.securityfocus.com/bid/21799http://www.vupen.com/english/advisories/2006/5193https://exchange.xforce.ibmcloud.com/vulnerabilities/31177https://www.exploit-db.com/exploits/3029
2006-12-28
Published