Cacti < 0.8.8b Command and SQL Injections

high Nessus Network Monitor Plugin ID 8004

Synopsis

A web application hosted on the remote web server is affected by command injection and SQL injection vulnerabilities

Description

Cacti is a network graphing solution designed to use the power of RRDTool's data storage and graphing functionality. According to its self-reported version number, the version of Cacti hosted on the remote web server is affected by command injection and SQL injection vulnerabilities because the application fails to properly sanitize user-supplied input.

An attacker may be able to leverage these issues to execute arbitrary code as well as access or modify the underlying database for the application

Solution

Upgrade to Cacti 0.8.8b or later.

See Also

http://www.cacti.net/release_notes_0_8_8b.php

http://permalink.gmane.org/gmane.comp.security.oss.general/10816

Plugin Details

Severity: High

ID: 8004

Family: Web Servers

Published: 9/5/2013

Updated: 3/6/2019

Nessus ID: 69306

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.2

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS v3

Risk Factor: High

Base Score: 7.3

Temporal Score: 6.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:cacti:cacti

Patch Publication Date: 8/5/2013

Vulnerability Publication Date: 8/5/2013

Reference Information

CVE: CVE-2013-1434, CVE-2013-1435

BID: 61657, 61847