CVE-2008-0786
published 2008-02-14CVE-2008-0786: CRLF injection vulnerability in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k, when running on older PHP interpreters, allows remote attackers to inject…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.77%
75.9th percentile
CRLF injection vulnerability in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k, when running on older PHP interpreters, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | >= 0 < 0.8.7b-1 | 0.8.7b-1 |
| cacti | cacti | >= 0 < 0.8.7b-1 | 0.8.7b-1 |
| cacti | cacti | >= 0 < 0.8.7b-1 | 0.8.7b-1 |
| cacti | cacti | >= 0 < 0.8.7b-1 | 0.8.7b-1 |
| debian | cacti | < cacti 0.8.7b-1 (bookworm) | cacti 0.8.7b-1 (bookworm) |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9m4h-7g4v-j826: CRLF injection vulnerability in Cacti 0
ghsa_unreviewed·2022-05-01
CVE-2008-0786 [MEDIUM] CWE-94 GHSA-9m4h-7g4v-j826: CRLF injection vulnerability in Cacti 0
CRLF injection vulnerability in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k, when running on older PHP interpreters, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
OSV
CVE-2008-0786: CRLF injection vulnerability in Cacti 0
osv·2008-02-14·CVSS 4.3
CVE-2008-0786 [MEDIUM] CVE-2008-0786: CRLF injection vulnerability in Cacti 0
CRLF injection vulnerability in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k, when running on older PHP interpreters, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Debian
CVE-2008-0786: cacti - CRLF injection vulnerability in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6...
vendor_debian·2008·CVSS 4.3
CVE-2008-0786 [MEDIUM] CVE-2008-0786: cacti - CRLF injection vulnerability in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6...
CRLF injection vulnerability in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k, when running on older PHP interpreters, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.8.7b-1)
bullseye: resolved (fixed in 0.8.7b-1)
forky: resolved (fixed in 0.8.7b-1)
sid: resolved (fixed in 0.8.7b-1)
trixie: resolved (fixed in 0.8.7b-1)
Red Hat
cacti: multiple input saintization issues (CVE-2008-0783, CVE-2008-0784, CVE-2008-0785, CVE-2008-0786)
vendor_redhat·CVSS 4.3
CVE-2008-0785 [MEDIUM] cacti: multiple input saintization issues (CVE-2008-0783, CVE-2008-0784, CVE-2008-0785, CVE-2008-0786)
cacti: multiple input saintization issues (CVE-2008-0783, CVE-2008-0784, CVE-2008-0785, CVE-2008-0786)
Multiple SQL injection vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote authenticated users to execute arbitrary SQL commands via the (1) graph_list parameter to graph_view.php, (2) leaf_id and id parameters to tree.php, (3) local_graph_id parameter to graph_xport.php, and (4) login_username parameter to index.php/login.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.htmlhttp://secunia.com/advisories/28872http://secunia.com/advisories/28976http://secunia.com/advisories/29242http://secunia.com/advisories/29274http://security.gentoo.org/glsa/glsa-200803-18.xmlhttp://securityreason.com/securityalert/3657http://www.cacti.net/release_notes_0_8_7b.phphttp://www.mandriva.com/security/advisories?name=MDVSA-2008:052http://www.securityfocus.com/archive/1/488013/100/0/threadedhttp://www.securityfocus.com/archive/1/488018/100/0/threadedhttp://www.securityfocus.com/bid/27749http://www.securitytracker.com/id?1019414http://www.vupen.com/english/advisories/2008/0540https://bugzilla.redhat.com/show_bug.cgi?id=432758https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00570.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-February/msg00593.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.htmlhttp://secunia.com/advisories/28872http://secunia.com/advisories/28976http://secunia.com/advisories/29242http://secunia.com/advisories/29274http://security.gentoo.org/glsa/glsa-200803-18.xmlhttp://securityreason.com/securityalert/3657http://www.cacti.net/release_notes_0_8_7b.phphttp://www.mandriva.com/security/advisories?name=MDVSA-2008:052http://www.securityfocus.com/archive/1/488013/100/0/threadedhttp://www.securityfocus.com/archive/1/488018/100/0/threadedhttp://www.securityfocus.com/bid/27749http://www.securitytracker.com/id?1019414http://www.vupen.com/english/advisories/2008/0540https://bugzilla.redhat.com/show_bug.cgi?id=432758https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00570.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-February/msg00593.html
2008-02-14
Published