CVE-2006-6799
SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL commands via the (1) second or (2) third arguments to cmd.php.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL commands via the (1) second or (2) third arguments to cmd.php. NOTE: this issue can be leveraged to execute arbitrary commands since the SQL query results are later used in the polling_items array and popen function.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.52% probability · 84th percentile
- CISA KEV
- Not listed
- Affected
- the cacti group/cacti
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/23528Vendor Advisory
- http://secunia.com/advisories/23665
- http://secunia.com/advisories/23917
- http://secunia.com/advisories/23941
- http://security.gentoo.org/glsa/glsa-200701-23.xml
- http://securitytracker.com/id?1017451
- http://www.cacti.net/release_notes_0_8_6j.php
- http://www.debian.org/security/2007/dsa-1250
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:015
- http://www.novell.com/linux/security/advisories/2007_07_cacti.html
- http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.001.html
- http://www.securityfocus.com/archive/1/457290/100/0/threaded
- http://www.securityfocus.com/bid/21799
- http://www.vupen.com/english/advisories/2006/5193
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31177
- https://www.exploit-db.com/exploits/3029
- http://secunia.com/advisories/23528Vendor Advisory
- http://secunia.com/advisories/23665
- http://secunia.com/advisories/23917
- http://secunia.com/advisories/23941
- http://security.gentoo.org/glsa/glsa-200701-23.xml
- http://securitytracker.com/id?1017451
- http://www.cacti.net/release_notes_0_8_6j.php
- http://www.debian.org/security/2007/dsa-1250
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:015
- http://www.novell.com/linux/security/advisories/2007_07_cacti.html
- http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.001.html
- http://www.securityfocus.com/archive/1/457290/100/0/threaded
- http://www.securityfocus.com/bid/21799
- http://www.vupen.com/english/advisories/2006/5193
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.