CVE-2005-2148
Last modified
CVE-2005-2148 is a vulnerability of currently unknown severity. Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitrary commands or SQL by sending a legitimate value in a POST request or cookie, then specifying the attack string in the URL, which causes the get_request_var function to return the wrong value in the $_REQUEST variable, which is cleansed while the original malicious $_GET value remains unmodified, as demonstrated in (1) graph_image.php and (2) graph.php.. EPSS estimates a 3.40% chance of exploitation in the next 30 days.
Description
Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitrary commands or SQL by sending a legitimate value in a POST request or cookie, then specifying the attack string in the URL, which causes the get_request_var function to return the wrong value in the $_REQUEST variable, which is cleansed while the original malicious $_GET value remains unmodified, as demonstrated in (1) graph_image.php and (2) graph.php.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| The Cacti Group | Cacti | 0.8 |
| The Cacti Group | Cacti | 0.8.1 |
| The Cacti Group | Cacti | 0.8.2 |
| The Cacti Group | Cacti | 0.8.2a |
| The Cacti Group | Cacti | 0.8.3 |
| The Cacti Group | Cacti | 0.8.3a |
| The Cacti Group | Cacti | 0.8.4 |
| The Cacti Group | Cacti | 0.8.5 |
| The Cacti Group | Cacti | 0.8.5a |
| The Cacti Group | Cacti | 0.8.6 |
| The Cacti Group | Cacti | 0.8.6a |
| The Cacti Group | Cacti | 0.8.6b |
| The Cacti Group | Cacti | 0.8.6c |
| The Cacti Group | Cacti | 0.8.6d |
| The Cacti Group | Cacti | 0.8.6e |
References
- http://www.hardened-php.net/advisory-032005.phpPatch, Vendor Advisory
- http://www.hardened-php.net/advisory-032005.phpPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-2148?
How severe is CVE-2005-2148?
How do I fix CVE-2005-2148?
Are you affected by CVE-2005-2148?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
