Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cacti HIGH 7.8
CVE-2007-3112

graph_image.php in Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a …

Fix: after 0.8.6i
Fix from $1,950 2007-06-07
Cacti MEDIUM 6.8
CVE-2007-3113

Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the …

Fix: after 0.8.6i
Fix from $1,600 2007-06-07
Cacti HIGH 7.5
CVE-2006-6799

SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL command…

Fix: after 0.8.6i
Fix from $1,950 2006-12-28
Cacti HIGH 10.0
CVE-2005-2149

config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges …

Patch available
Fix from $1,950 2005-07-06
Cacti HIGH 7.5
CVE-2005-2148

Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitra…

Patch available
Fix from $1,950 2005-07-06
Cacti HIGH 7.5
CVE-2005-1525

SQL injection vulnerability in config_settings.php for Cacti before 0.8.6e allows remote attackers to execute arbitrary SQL commands via the id param…

Fix: after 0.8.6d
Fix from $1,950 2005-06-22
Cacti HIGH 7.5
CVE-2005-1526EPSS 17%

PHP remote file inclusion vulnerability in config_settings.php in Cacti before 0.8.6e allows remote attackers to execute arbitrary PHP code via the c…

Fix: after 0.8.6d
Fix from $1,950 2005-06-22
Cacti MEDIUM 5.0
CVE-2005-1524EPSS 16%

PHP file inclusion vulnerability in top_graph_header.php in Cacti 0.8.6d and possibly earlier versions allows remote attackers to execute arbitrary P…

Fix: after 0.8.6d
Fix from $1,600 2005-06-22
Cacti MEDIUM 5.0
CVE-2004-1736

Cacti 0.8.5a allows remote attackers to gain sensitive information via an HTTP request to (1) auth.php, (2) auth_login.php, (3) auth_changepassword.p…

No fix yet
Fix from $1,600 2004-12-31
Cacti HIGH 10.0
CVE-2002-1478

Cacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode.

Patch available
Fix from $1,950 2003-04-22
Cacti HIGH 7.5
CVE-2002-1477

graphs.php in Cacti before 0.6.8 allows remote authenticated Cacti administrators to execute arbitrary commands via shell metacharacters in the title…

Patch available
Fix from $1,950 2003-04-22