CVE-2010-1645
published 2010-08-23CVE-2010-1645: Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products, allows remote authenticated administrators to execute…
PriorityP340medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
2.80%
85.0th percentile
Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products, allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in (1) the FQDN field of a Device or (2) the Vertical Label field of a Graph Template.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cacti | cacti | <= 0.8.7e | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cacti: multiple command injection flaws (BONSAI-2010-0105)
vendor_redhat·2010-05-20·CVSS 6.5
CVE-2010-1645 [MEDIUM] cacti: multiple command injection flaws (BONSAI-2010-0105)
cacti: multiple command injection flaws (BONSAI-2010-0105)
Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products, allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in (1) the FQDN field of a Device or (2) the Vertical Label field of a Graph Template.
Debian
CVE-2010-1645: cacti - Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solutio...
vendor_debian·2010·CVSS 6.5
CVE-2010-1645 [MEDIUM] CVE-2010-1645: cacti - Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solutio...
Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products, allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in (1) the FQDN field of a Device or (2) the Vertical Label field of a Graph Template.
Scope: local
bookworm: resolved (fixed in 0.8.7g-1)
bullseye: resolved (fixed in 0.8.7g-1)
forky: resolved (fixed in 0.8.7g-1)
sid: resolved (fixed in 0.8.7g-1)
trixie: resolved (fixed in 0.8.7g-1)
GHSA
GHSA-3cv5-x4w9-vjq6: Cacti before 0
ghsa_unreviewed·2022-05-17
CVE-2010-1645 [MEDIUM] CWE-20 GHSA-3cv5-x4w9-vjq6: Cacti before 0
Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products, allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in (1) the FQDN field of a Device or (2) the Vertical Label field of a Graph Template.
OSV
CVE-2010-1645: Cacti before 0
osv·2010-08-23·CVSS 6.5
CVE-2010-1645 [MEDIUM] CVE-2010-1645: Cacti before 0
Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products, allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in (1) the FQDN field of a Device or (2) the Vertical Label field of a Graph Template.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-1645 cacti: multiple command injection flaws (BONSAI-2010-0105)
bugzilla·2010-06-29·CVSS 6.5
CVE-2010-1645 [MEDIUM] CVE-2010-1645 cacti: multiple command injection flaws (BONSAI-2010-0105)
CVE-2010-1645 cacti: multiple command injection flaws (BONSAI-2010-0105)
Multiple input sanitization flaws were discovered in cacti. Authenticated cacti administrator could use these flaws to run shell commands with web server privileges.
Note: cacti administrator is always allowed to run commands as cacti user.
References:
http://www.bonsai-sec.com/en/research/vulnerabilities/cacti-os-command-injection-0105.php
http://www.cacti.net/release_notes_0_8_7f.php
Upstream commits:
http://svn.cacti.net/viewvc?view=rev&revision=5778
http://svn.cacti.net/viewvc?view=rev&revision=5782
http://svn.cacti.net/viewvc?view=rev&revision=5784
See also bug #595289 for some related discussion.
Discussion:
*** Bug 586064 has been marked as a duplicate of this bug. ***
---
This issue has been addressed
Bugzilla
CVE-2010-1644 CVE-2010-1645 CVE-2010-2092 Cacti v0.8.7f - three security fixes
bugzilla·2010-05-24·CVSS 4.3
CVE-2010-1644 [MEDIUM] CVE-2010-1644 CVE-2010-1645 CVE-2010-2092 Cacti v0.8.7f - three security fixes
CVE-2010-1644 CVE-2010-1645 CVE-2010-2092 Cacti v0.8.7f - three security fixes
Cacti upstream has released:
[1] http://www.cacti.net/release_notes_0_8_7f.php
latest v0.8.7 version, addressing three security flaws:
[A], MOPS-2010-023: Cacti Graph Viewer SQL Injection Vulnerability
[2] http://php-security.org/2010/05/13/mops-2010-023-cacti-graph-viewer-sql-injection-vulnerability/index.html
[3] http://www.vupen.com/english/advisories/2010/1204
Credit: The vulnerability was discovered by Stefan Esser as part
of the SQL Injection Marathon.
Upstream changeset:
[4] http://svn.cacti.net/viewvc?view=rev&revision=5920
[B], Cross-site scripting issues reported by VUPEN Security
(http://www.vupen.com)
[5] http://www.vupen.com/english/advisories/2010/1203
Credit: Vulnerabilities reported by Moham
http://secunia.com/advisories/41041http://svn.cacti.net/viewvc?view=rev&revision=5778http://svn.cacti.net/viewvc?view=rev&revision=5782http://svn.cacti.net/viewvc?view=rev&revision=5784http://www.bonsai-sec.com/en/research/vulnerabilities/cacti-os-command-injection-0105.phphttp://www.cacti.net/release_notes_0_8_7f.phphttp://www.mandriva.com/security/advisories?name=MDVSA-2010:160http://www.vupen.com/english/advisories/2010/2132https://bugzilla.redhat.com/show_bug.cgi?id=609115https://rhn.redhat.com/errata/RHSA-2010-0635.htmlhttp://secunia.com/advisories/41041http://svn.cacti.net/viewvc?view=rev&revision=5778http://svn.cacti.net/viewvc?view=rev&revision=5782http://svn.cacti.net/viewvc?view=rev&revision=5784http://www.bonsai-sec.com/en/research/vulnerabilities/cacti-os-command-injection-0105.phphttp://www.cacti.net/release_notes_0_8_7f.phphttp://www.mandriva.com/security/advisories?name=MDVSA-2010:160http://www.vupen.com/english/advisories/2010/2132https://bugzilla.redhat.com/show_bug.cgi?id=609115https://rhn.redhat.com/errata/RHSA-2010-0635.html
2010-08-23
Published