Debian Cacti vulnerabilities
155 known vulnerabilities affecting debian/cacti.
Total CVEs
155
CISA KEV
1
actively exploited
Public exploits
25
Exploited in wild
3
Severity breakdown
CRITICAL10HIGH50MEDIUM72LOW23
Vulnerabilities
Page 2 of 8
CVE-2021-26247P3MEDIUMCVSS 6.1PoCfixed in cacti 0.8.7i-1 (bookworm)2021
CVE-2021-26247 [MEDIUM] CVE-2021-26247: cacti - As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassw...
As an unauthenticated remote user, visit "http:///auth_changepassword.php?ref=alert(1)" to successfully execute the JavaScript payload present in the "ref" URL parameter.
Scope: local
bookworm: resolved (fixed in 0.8.7i-1)
bullseye: resolved (fixed in 0.8.7i-1)
forky: resolved (fixed in 0.8.7i-1)
sid: resolved (fixed in 0.8.7i-1)
trixie: resolved (fixed in 0.8.7i-1)
debian
CVE-2004-1737P3HIGHCVSS 7.5PoCfixed in cacti 0.8.5a-5 (bookworm)2004
CVE-2004-1737 [HIGH] CVE-2004-1737: cacti - SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote atta...
SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters.
Scope: local
bookworm: resolved (fixed in 0.8.5a-5)
bullseye: resolved (fixed in 0.8.5a-5)
forky: resolved (fixed in 0.8.5a-5)
sid: resolved (fixed in 0.8.5a-5)
trixie: resolved
debian
CVE-2024-43363P2HIGHCVSS 7.2fixed in cacti 1.2.24+ds1-1+deb12u5 (bookworm)2024
CVE-2024-43363 [HIGH] CVE-2024-43363: cacti - Cacti is an open source performance and fault management framework. An admin use...
Cacti is an open source performance and fault management framework. An admin user can create a device with a malicious hostname containing php code and repeat the installation process (completing only step 5 of the installation process is enough, no need to complete the steps before or after it) to use a php file as the cacti log file. After having the malicious hostn
debian
CVE-2008-0785P3LOWCVSS 7.5PoCfixed in cacti 0.8.7b-1 (bookworm)2008
CVE-2008-0785 [HIGH] CVE-2008-0785: cacti - Multiple SQL injection vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 be...
Multiple SQL injection vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote authenticated users to execute arbitrary SQL commands via the (1) graph_list parameter to graph_view.php, (2) leaf_id and id parameters to tree.php, (3) local_graph_id parameter to graph_xport.php, and (4) login_username parameter to index.php/login.
Scope: local
boo
debian
CVE-2005-1524P3HIGHCVSS 5.0PoCfixed in cacti 0.8.6e-1 (bookworm)2005
CVE-2005-1524 [MEDIUM] CVE-2005-1524: cacti - PHP file inclusion vulnerability in top_graph_header.php in Cacti 0.8.6d and pos...
PHP file inclusion vulnerability in top_graph_header.php in Cacti 0.8.6d and possibly earlier versions allows remote attackers to execute arbitrary PHP code via the config[library_path] parameter.
Scope: local
bookworm: resolved (fixed in 0.8.6e-1)
bullseye: resolved (fixed in 0.8.6e-1)
forky: resolved (fixed in 0.8.6e-1)
sid: resolved (fixed in 0.8.6e-1)
trixie: reso
debian
CVE-2024-31460P2MEDIUMCVSS 6.5fixed in cacti 1.2.24+ds1-1+deb12u3 (bookworm)2024
CVE-2024-31460 [MEDIUM] CVE-2024-31460: cacti - Cacti provides an operational monitoring and fault management framework. Prior t...
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the SQL statement in `create_all_header_nodes()` function from `lib/api_automation.php` , finally resulting in SQL injection. Using SQL based secondary injection
debian
CVE-2023-39357P2HIGHCVSS 8.8fixed in cacti 1.2.24+ds1-1+deb12u1 (bookworm)2023
CVE-2023-39357 [HIGH] CVE-2023-39357: cacti - Cacti is an open source operational monitoring and fault management framework. A...
Cacti is an open source operational monitoring and fault management framework. A defect in the sql_save function was discovered. When the column type is numeric, the sql_save function directly utilizes user input. Many files and functions calling the sql_save function do not perform prior validation of user input, leading to the existence of multiple SQL injection vul
debian
CVE-2023-39358P2HIGHCVSS 8.8fixed in cacti 1.2.24+ds1-1+deb12u1 (bookworm)2023
CVE-2023-39358 [HIGH] CVE-2023-39358: cacti - Cacti is an open source operational monitoring and fault management framework. A...
Cacti is an open source operational monitoring and fault management framework. An authenticated SQL injection vulnerability was discovered which allows authenticated users to perform privilege escalation and remote code execution. The vulnerability resides in the `reports_user.php` file. In `ajax_get_branches`, the `tree_id` parameter is passed to the `reports_get_bra
debian
CVE-2019-17357P3MEDIUMCVSS 6.5fixed in cacti 1.2.8+ds1-1 (bookworm)2019
CVE-2019-17357 [MEDIUM] CVE-2019-17357: cacti - Cacti through 1.2.7 is affected by a graphs.php?template_id= SQL injection vulne...
Cacti through 1.2.7 is affected by a graphs.php?template_id= SQL injection vulnerability affecting how template identifiers are handled when a string and id composite value are used to identify the template type and id. An authenticated attacker can exploit this to extract data from the database, or an unauthenticated remote attacker could exploit this via Cross-Sit
debian
CVE-2022-0730P3CRITICALCVSS 9.8fixed in cacti 1.2.20+ds1-1 (bookworm)2022
CVE-2022-0730 [CRITICAL] CVE-2022-0730: cacti - Under certain ldap conditions, Cacti authentication can be bypassed with certain...
Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.
Scope: local
bookworm: resolved (fixed in 1.2.20+ds1-1)
bullseye: resolved (fixed in 1.2.16+ds1-2+deb11u1)
forky: resolved (fixed in 1.2.20+ds1-1)
sid: resolved (fixed in 1.2.20+ds1-1)
trixie: resolved (fixed in 1.2.20+ds1-1)
debian
CVE-2020-35701P3HIGHCVSS 8.8fixed in cacti 1.2.16+ds1-2 (bookworm)2020
CVE-2020-35701 [HIGH] CVE-2020-35701: cacti - An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerabi...
An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in data_debug.php allows remote authenticated attackers to execute arbitrary SQL commands via the site_id parameter. This can lead to remote code execution.
Scope: local
bookworm: resolved (fixed in 1.2.16+ds1-2)
bullseye: resolved (fixed in 1.2.16+ds1-2)
forky: resolved (fixed in 1.2
debian
CVE-2023-39359P3HIGHCVSS 8.8fixed in cacti 1.2.24+ds1-1+deb12u1 (bookworm)2023
CVE-2023-39359 [HIGH] CVE-2023-39359: cacti - Cacti is an open source operational monitoring and fault management framework. A...
Cacti is an open source operational monitoring and fault management framework. An authenticated SQL injection vulnerability was discovered which allows authenticated users to perform privilege escalation and remote code execution. The vulnerability resides in the `graphs.php` file. When dealing with the cases of ajax_hosts and ajax_hosts_noany, if the `site_id` parame
debian
CVE-2014-5261P3HIGHCVSS 7.5fixed in cacti 0.8.8b+dfsg-8 (bookworm)2014
CVE-2014-5261 [HIGH] CVE-2014-5261: cacti - The graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allow...
The graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a font size, related to the rrdtool commandline in lib/rrd.php.
Scope: local
bookworm: resolved (fixed in 0.8.8b+dfsg-8)
bullseye: resolved (fixed in 0.8.8b+dfsg-8)
forky: resolved (fixed in 0.8.8b+dfsg-8)
sid: reso
debian
CVE-2024-43364P3MEDIUMCVSS 5.7fixed in cacti 1.2.24+ds1-1+deb12u5 (bookworm)2024
CVE-2024-43364 [MEDIUM] CVE-2024-43364: cacti - Cacti is an open source performance and fault management framework. The `title` ...
Cacti is an open source performance and fault management framework. The `title` parameter is not properly sanitized when saving external links in links.php . Morever, the said title parameter is stored in the database and reflected back to user in index.php, finally leading to stored XSS. Users with the privilege to create external links can manipulate the `title` p
debian
CVE-2017-12065P3CRITICALCVSS 9.8fixed in cacti 1.1.16+ds1-1 (bookworm)2017
CVE-2017-12065 [CRITICAL] CVE-2017-12065: cacti - spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arb...
spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter.
Scope: local
bookworm: resolved (fixed in 1.1.16+ds1-1)
bullseye: resolved (fixed in 1.1.16+ds1-1)
forky: resolved (fixed in 1.1.16+ds1-1)
sid: resolved (fixed in 1.1.16+ds1-1)
trixie: resolved (fixed in 1.1.16+ds1-1)
debian
CVE-2024-31458P3MEDIUMCVSS 4.6fixed in cacti 1.2.24+ds1-1+deb12u3 (bookworm)2024
CVE-2024-31458 [MEDIUM] CVE-2024-31458: cacti - Cacti provides an operational monitoring and fault management framework. Prior t...
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `form_save()` function in `graph_template_inputs.php` is not thoroughly checked and is used to concatenate the SQL statement in `draw_nontemplated_fields_graph_item()` function from `lib/html_form_templates.php` , finally resulting in SQL inje
debian
CVE-2016-2313P3HIGHCVSS 8.8fixed in cacti 0.8.8g+ds1-1 (bookworm)2016
CVE-2016-2313 [HIGH] CVE-2016-2313: cacti - auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use ...
auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
Scope: local
bookworm: resolved (fixed in 0.8.8g+ds1-1)
bullseye: resolved (fixed in 0.8.8g+ds1-1)
forky: resolved (fixed in 0.8.8g+ds1-1)
sid: resolved (fixed in 0.8.8g+ds1-1)
trixie
debian
CVE-2015-8604P3HIGHCVSS 8.8fixed in cacti 0.8.8f+ds1-4 (bookworm)2015
CVE-2015-8604 [HIGH] CVE-2015-8604: cacti - SQL injection vulnerability in the host_new_graphs function in graphs_new.php in...
SQL injection vulnerability in the host_new_graphs function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via the cg_g parameter in a save action.
Scope: local
bookworm: resolved (fixed in 0.8.8f+ds1-4)
bullseye: resolved (fixed in 0.8.8f+ds1-4)
forky: resolved (fixed in 0.8.8f+ds1-4)
sid: resolved (fix
debian
CVE-2024-34340P3CRITICALCVSS 9.1fixed in cacti 1.2.24+ds1-1+deb12u3 (bookworm)2024
CVE-2024-34340 [CRITICAL] CVE-2024-34340: cacti - Cacti provides an operational monitoring and fault management framework. Prior t...
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set their password. `compat_password_hash` use `password_hash` if there is it, else use `md5`. When verifying password, it calls `compat_password_verify`. In `compat_password_verify`, `password_verify` is called if there i
debian
CVE-2017-1000031P3HIGHCVSS 8.8fixed in cacti 0.8.8e+ds1-1 (bookworm)2017
CVE-2017-1000031 [HIGH] CVE-2017-1000031: cacti - SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows...
SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary SQL commands via the graph_template_input_id and graph_template_id parameters.
Scope: local
bookworm: resolved (fixed in 0.8.8e+ds1-1)
bullseye: resolved (fixed in 0.8.8e+ds1-1)
forky: resolved (fixed in 0.8.8e+ds1-1)
sid: resolved (fixed in 0.8.8
debian