cbcvebase.

Debian Cacti vulnerabilities

155 known vulnerabilities affecting debian/cacti.

Total CVEs
155
CISA KEV
1
actively exploited
Public exploits
25
Exploited in wild
3
Severity breakdown
CRITICAL10HIGH50MEDIUM72LOW23

Vulnerabilities

Page 5 of 8
CVE-2005-2148P3HIGHCVSS 7.5fixed in cacti 0.8.6f-1 (bookworm)2005
CVE-2005-2148 [HIGH] CVE-2005-2148: cacti - Cacti 0.8.6e and earlier does not perform proper input validation to protect aga... Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitrary commands or SQL by sending a legitimate value in a POST request or cookie, then specifying the attack string in the URL, which causes the get_request_var function to return the wrong value in the $_REQUEST variable, whic
debian
CVE-2005-2149P4HIGHCVSS 10.0fixed in cacti 0.8.6f-1 (bookworm)2005
CVE-2005-2149 [CRITICAL] CVE-2005-2149: cacti - config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_htt... config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks. Scope: local bookworm: resolved (fixed in 0.8.6f-1) bullseye: resolved (fixed in 0.8.6f-1) forky: resolved (fixed in 0.8.6f-1) sid: resolved (fixed in
debian
CVE-2024-31444P4MEDIUMCVSS 4.6fixed in cacti 1.2.24+ds1-1+deb12u3 (bookworm)2024
CVE-2024-31444 [MEDIUM] CVE-2024-31444: cacti - Cacti provides an operational monitoring and fault management framework. Prior t... Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules_form_save()` function in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the HTML statement in `form_confirm()` function from `lib/html.php` , finally resulting in cross-site scripting. V
debian
CVE-2023-39365P3MEDIUMCVSS 4.6fixed in cacti 1.2.24+ds1-1+deb12u1 (bookworm)2023
CVE-2023-39365 [MEDIUM] CVE-2023-39365: cacti - Cacti is an open source operational monitoring and fault management framework. I... Cacti is an open source operational monitoring and fault management framework. Issues with Cacti Regular Expression validation combined with the external links feature can lead to limited SQL Injections and subsequent data leakage. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability. Sc
debian
CVE-2002-1478P4CRITICALCVSS 10.0fixed in cacti 0.6.8a-2 (bookworm)2002
CVE-2002-1478 [CRITICAL] CVE-2002-1478: cacti - Cacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data ... Cacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode. Scope: local bookworm: resolved (fixed in 0.6.8a-2) bullseye: resolved (fixed in 0.6.8a-2) forky: resolved (fixed in 0.6.8a-2) sid: resolved (fixed in 0.6.8a-2) trixie: resolved (fixed in 0.6.8a-2)
debian
CVE-2015-0916P4HIGHCVSS 7.5fixed in cacti 0.8.6f-1 (bookworm)2015
CVE-2015-0916 [HIGH] CVE-2015-0916: cacti - SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote au... SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote authenticated users to execute arbitrary SQL commands via the local_graph_id parameter, a different vulnerability than CVE-2007-6035. Scope: local bookworm: resolved (fixed in 0.8.6f-1) bullseye: resolved (fixed in 0.8.6f-1) forky: resolved (fixed in 0.8.6f-1) sid: resolved (fixed in 0.8.6f-1)
debian
CVE-2006-0410P4MEDIUMCVSS 5.0fixed in cacti 0.8.6d-1 (bookworm)2006
CVE-2006-0410 [MEDIUM] CVE-2006-0410: cacti - SQL injection vulnerability in ADOdb before 4.71, when using PostgreSQL, allows ... SQL injection vulnerability in ADOdb before 4.71, when using PostgreSQL, allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors involving binary strings. Scope: local bookworm: resolved (fixed in 0.8.6d-1) bullseye: resolved (fixed in 0.8.6d-1) forky: resolved (fixed in 0.8.6d-1) sid: resolved (fixed in 0.8.6d-1) trixie: resolved (fix
debian
CVE-2002-1477P4HIGHCVSS 7.5fixed in cacti 0.6.8a-2 (bookworm)2002
CVE-2002-1477 [HIGH] CVE-2002-1477: cacti - graphs.php in Cacti before 0.6.8 allows remote authenticated Cacti administrator... graphs.php in Cacti before 0.6.8 allows remote authenticated Cacti administrators to execute arbitrary commands via shell metacharacters in the title during edit mode. Scope: local bookworm: resolved (fixed in 0.6.8a-2) bullseye: resolved (fixed in 0.6.8a-2) forky: resolved (fixed in 0.6.8a-2) sid: resolved (fixed in 0.6.8a-2) trixie: resolved (fixed in 0.6.8a-2)
debian
CVE-2005-1525P4HIGHCVSS 7.5fixed in cacti 0.8.6e-1 (bookworm)2005
CVE-2005-1525 [HIGH] CVE-2005-1525: cacti - SQL injection vulnerability in config_settings.php for Cacti before 0.8.6e allow... SQL injection vulnerability in config_settings.php for Cacti before 0.8.6e allows remote attackers to execute arbitrary SQL commands via the id parameter. Scope: local bookworm: resolved (fixed in 0.8.6e-1) bullseye: resolved (fixed in 0.8.6e-1) forky: resolved (fixed in 0.8.6e-1) sid: resolved (fixed in 0.8.6e-1) trixie: resolved (fixed in 0.8.6e-1)
debian
CVE-2022-48538P4LOWCVSS 5.3fixed in cacti 1.2.23+ds1-1 (bookworm)2022
CVE-2022-48538 [MEDIUM] CVE-2022-48538: cacti - In Cacti 1.2.19, there is an authentication bypass in the web login functionalit... In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() allows a zero as the password. Scope: local bookworm: resolved (fixed in 1.2.23+ds1-1) bullseye: open forky: resolved (fixed in 1.2.23+ds1-1) sid: resolved (fixed in 1.2.23+ds1-1) trixie: resolved (fixed in 1.2.23+ds1-1)
debian
CVE-2014-2327P4MEDIUMCVSS 6.8fixed in cacti 0.8.8b+dfsg-6 (bookworm)2014
CVE-2014-2327 [MEDIUM] CVE-2014-2327: cacti - Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and ear... Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users for unspecified commands, as demonstrated by requests that (1) modify binary files, (2) modify configurations, or (3) add arbitrary users. Scope: local bookworm: resolved (fixed in 0.8.8b+dfsg-6) bullseye: resolved (fixed i
debian
CVE-2025-45160P4MEDIUMCVSS 5.4fixed in cacti 1.2.24+ds1-1+deb12u3 (bookworm)2025
CVE-2025-45160 [MEDIUM] CVE-2025-45160: cacti - A HTML injection vulnerability exists in the file upload functionality of Cacti ... A HTML injection vulnerability exists in the file upload functionality of Cacti , , ) into the rendered page. NOTE: Multiple third-parties including the maintainer have stated that they cannot reproduce this issue after 1.2.27. Scope: local bookworm: resolved (fixed in 1.2.24+ds1-1+deb12u3) bullseye: open forky: resolved (fixed in 1.2.27+ds1-1) sid: resolved (fixed
debian
CVE-2020-7106P4MEDIUMCVSS 6.1fixed in cacti 1.2.9+ds1-1 (bookworm)2020
CVE-2020-7106 [MEDIUM] CVE-2020-7106: cacti - Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs... Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS). Scope: local bookworm: resolved (fixed in 1.2.9+ds1-1)
debian
CVE-2020-14424P4MEDIUMCVSS 6.1fixed in cacti 1.2.19+ds1-1 (bookworm)2020
CVE-2020-14424 [MEDIUM] CVE-2020-14424: cacti - Cacti before 1.2.18 allows remote attackers to trigger XSS via template import f... Cacti before 1.2.18 allows remote attackers to trigger XSS via template import for the midwinter theme. Scope: local bookworm: resolved (fixed in 1.2.19+ds1-1) bullseye: resolved forky: resolved (fixed in 1.2.19+ds1-1) sid: resolved (fixed in 1.2.19+ds1-1) trixie: resolved (fixed in 1.2.19+ds1-1)
debian
CVE-2023-49086P4MEDIUMCVSS 6.1fixed in cacti 1.2.24+ds1-1+deb12u2 (bookworm)2023
CVE-2023-49086 [MEDIUM] CVE-2023-49086: cacti - Cacti is a robust performance and fault management framework and a frontend to R... Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). A vulnerability in versions prior to 1.2.27 bypasses an earlier fix for CVE-2023-39360, therefore leading to a DOM XSS attack. Exploitation of the vulnerability is possible for an authorized user. The vulnerable component is the `graphs_new.php`. T
debian
CVE-2023-50250P4MEDIUMCVSS 5.4fixed in cacti 1.2.24+ds1-1+deb12u2 (bookworm)2023
CVE-2023-50250 [MEDIUM] CVE-2023-50250: cacti - Cacti is an open source operational monitoring and fault management framework. A... Cacti is an open source operational monitoring and fault management framework. A reflection cross-site scripting vulnerability was discovered in version 1.2.25. Attackers can exploit this vulnerability to perform actions on behalf of other users. The vulnerability is found in `templates_import.php.` When uploading an xml template file, if the XML file does not pass
debian
CVE-2017-16661P4MEDIUMCVSS 4.9fixed in cacti 1.1.27+ds1-3 (bookworm)2017
CVE-2017-16661 [MEDIUM] CVE-2017-16661: cacti - Cacti 1.1.27 allows remote authenticated administrators to read arbitrary files ... Cacti 1.1.27 allows remote authenticated administrators to read arbitrary files by placing the Log Path into a private directory, and then making a clog.php?filename= request, as demonstrated by filename=passwd (with a Log Path under /etc) to read /etc/passwd. Scope: local bookworm: resolved (fixed in 1.1.27+ds1-3) bullseye: resolved (fixed in 1.1.27+ds1-3) forky: r
debian
CVE-2024-45598P4MEDIUMCVSS 6.0fixed in cacti 1.2.24+ds1-1+deb12u5 (bookworm)2024
CVE-2024-45598 [MEDIUM] CVE-2024-45598: cacti - Cacti is an open source performance and fault management framework. Prior to 1.2... Cacti is an open source performance and fault management framework. Prior to 1.2.29, an administrator can change the `Poller Standard Error Log Path` parameter in either Installation Step 5 or in Configuration->Settings->Paths tab to a local file inside the server. Then simply going to Logs tab and selecting the name of the local file will show its content on the we
debian
CVE-2020-23226P4MEDIUMCVSS 6.1fixed in cacti 1.2.13+ds1-1 (bookworm)2020
CVE-2020-23226 [MEDIUM] CVE-2020-23226: cacti - Multiple Cross Site Scripting (XSS) vulneratiblities exist in Cacti 1.2.12 in (1... Multiple Cross Site Scripting (XSS) vulneratiblities exist in Cacti 1.2.12 in (1) reports_admin.php, (2) data_queries.php, (3) data_input.php, (4) graph_templates.php, (5) graphs.php, (6) reports_admin.php, and (7) data_input.php. Scope: local bookworm: resolved (fixed in 1.2.13+ds1-1) bullseye: resolved (fixed in 1.2.13+ds1-1) forky: resolved (fixed in 1.2.13+ds1-1
debian
CVE-2023-39364P4LOWCVSS 3.5fixed in cacti 1.2.24+ds1-1+deb12u1 (bookworm)2023
CVE-2023-39364 [LOW] CVE-2023-39364: cacti - Cacti is an open source operational monitoring and fault management framework. I... Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, users with console access can be redirected to an arbitrary website after a change password performed via a specifically crafted URL. The `auth_changepassword.php` file accepts `ref` as a URL parameter and reflects it in the form used to perform the change password. It's val
debian
Debian Cacti vulnerabilities | cvebase