CVE-2008-0784
published 2008-02-14CVE-2008-0784: graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allows remote attackers to obtain the full path via an invalid local_graph_id parameter and…
PriorityP422medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.22%
80.8th percentile
graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allows remote attackers to obtain the full path via an invalid local_graph_id parameter and other unspecified vectors.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | >= 0 < 0.8.7b-1 | 0.8.7b-1 |
| cacti | cacti | >= 0 < 0.8.7b-1 | 0.8.7b-1 |
| cacti | cacti | >= 0 < 0.8.7b-1 | 0.8.7b-1 |
| cacti | cacti | >= 0 < 0.8.7b-1 | 0.8.7b-1 |
| debian | cacti | < cacti 0.8.7b-1 (bookworm) | cacti 0.8.7b-1 (bookworm) |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q255-j47v-gc2r: graph
ghsa_unreviewed·2022-05-01
CVE-2008-0784 [MEDIUM] CWE-200 GHSA-q255-j47v-gc2r: graph
graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allows remote attackers to obtain the full path via an invalid local_graph_id parameter and other unspecified vectors.
OSV
CVE-2008-0784: graph
osv·2008-02-14·CVSS 5.0
CVE-2008-0784 [MEDIUM] CVE-2008-0784: graph
graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allows remote attackers to obtain the full path via an invalid local_graph_id parameter and other unspecified vectors.
Debian
CVE-2008-0784: cacti - graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allows remote att...
vendor_debian·2008·CVSS 5.0
CVE-2008-0784 [MEDIUM] CVE-2008-0784: cacti - graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allows remote att...
graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allows remote attackers to obtain the full path via an invalid local_graph_id parameter and other unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.8.7b-1)
bullseye: resolved (fixed in 0.8.7b-1)
forky: resolved (fixed in 0.8.7b-1)
sid: resolved (fixed in 0.8.7b-1)
trixie: resolved (fixed in 0.8.7b-1)
Red Hat
cacti: multiple input saintization issues (CVE-2008-0783, CVE-2008-0784, CVE-2008-0785, CVE-2008-0786)
vendor_redhat·CVSS 4.3
CVE-2008-0785 [MEDIUM] cacti: multiple input saintization issues (CVE-2008-0783, CVE-2008-0784, CVE-2008-0785, CVE-2008-0786)
cacti: multiple input saintization issues (CVE-2008-0783, CVE-2008-0784, CVE-2008-0785, CVE-2008-0786)
Multiple SQL injection vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote authenticated users to execute arbitrary SQL commands via the (1) graph_list parameter to graph_view.php, (2) leaf_id and id parameters to tree.php, (3) local_graph_id parameter to graph_xport.php, and (4) login_username parameter to index.php/login.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.htmlhttp://secunia.com/advisories/28872http://secunia.com/advisories/28976http://secunia.com/advisories/29242http://secunia.com/advisories/29274http://security.gentoo.org/glsa/glsa-200803-18.xmlhttp://securityreason.com/securityalert/3657http://www.cacti.net/release_notes_0_8_7b.phphttp://www.mandriva.com/security/advisories?name=MDVSA-2008:052http://www.securityfocus.com/archive/1/488013/100/0/threadedhttp://www.securityfocus.com/archive/1/488018/100/0/threadedhttp://www.securityfocus.com/bid/27749http://www.securitytracker.com/id?1019414http://www.vupen.com/english/advisories/2008/0540https://bugzilla.redhat.com/show_bug.cgi?id=432758https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00570.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-February/msg00593.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.htmlhttp://secunia.com/advisories/28872http://secunia.com/advisories/28976http://secunia.com/advisories/29242http://secunia.com/advisories/29274http://security.gentoo.org/glsa/glsa-200803-18.xmlhttp://securityreason.com/securityalert/3657http://www.cacti.net/release_notes_0_8_7b.phphttp://www.mandriva.com/security/advisories?name=MDVSA-2008:052http://www.securityfocus.com/archive/1/488013/100/0/threadedhttp://www.securityfocus.com/archive/1/488018/100/0/threadedhttp://www.securityfocus.com/bid/27749http://www.securitytracker.com/id?1019414http://www.vupen.com/english/advisories/2008/0540https://bugzilla.redhat.com/show_bug.cgi?id=432758https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00570.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-February/msg00593.html
2008-02-14
Published