10
CVE-2005-2149
- EPSS 1.29%
- Veröffentlicht 06.07.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
- Quelle security@debian.org
- CVE-Watchlists
- Unerledigt
config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
The Cacti Group ≫ Cacti Version0.8
The Cacti Group ≫ Cacti Version0.8.1
The Cacti Group ≫ Cacti Version0.8.2
The Cacti Group ≫ Cacti Version0.8.2a
The Cacti Group ≫ Cacti Version0.8.3
The Cacti Group ≫ Cacti Version0.8.3a
The Cacti Group ≫ Cacti Version0.8.4
The Cacti Group ≫ Cacti Version0.8.5
The Cacti Group ≫ Cacti Version0.8.5a
The Cacti Group ≫ Cacti Version0.8.6
The Cacti Group ≫ Cacti Version0.8.6a
The Cacti Group ≫ Cacti Version0.8.6b
The Cacti Group ≫ Cacti Version0.8.6c
The Cacti Group ≫ Cacti Version0.8.6d
The Cacti Group ≫ Cacti Version0.8.6e
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.29% | 0.778 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|