4.6

CVE-2002-1479

Exploit

Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users to modify databases as the Cacti user and possibly gain privileges.

Data is provided by the National Vulnerability Database (NVD)
The Cacti GroupCacti Version0.5
The Cacti GroupCacti Version0.6
The Cacti GroupCacti Version0.6.1
The Cacti GroupCacti Version0.6.2
The Cacti GroupCacti Version0.6.3
The Cacti GroupCacti Version0.6.4
The Cacti GroupCacti Version0.6.5
The Cacti GroupCacti Version0.6.6
The Cacti GroupCacti Version0.6.7
The Cacti GroupCacti Version0.6.8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.128
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P