CVE-2005-2148

N/A Unknown
Published: July 06, 2005 Modified: April 16, 2026
View on NVD

Description

Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitrary commands or SQL by sending a legitimate value in a POST request or cookie, then specifying the attack string in the URL, which causes the get_request_var function to return the wrong value in the $_REQUEST variable, which is cleansed while the original malicious $_GET value remains unmodified, as demonstrated in (1) graph_image.php and (2) graph.php.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/15490
Source: security@debian.org
http://securitytracker.com/id?1014361
Source: security@debian.org
http://www.hardened-php.net/advisory-032005.php
Source: security@debian.org
Patch Vendor Advisory
http://www.hardened-php.net/advisory-042005.php
Source: security@debian.org
Patch
http://www.securityfocus.com/bid/14128
Source: security@debian.org
http://www.securityfocus.com/bid/14129
Source: security@debian.org
http://secunia.com/advisories/15490
Source: af854a3a-2127-422b-91ae-364da2661108
http://securitytracker.com/id?1014361
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.cacti.net/downloads/patches/0.8.6e/cacti-0.8.6f_security.patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
http://www.debian.org/security/2005/dsa-764
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.hardened-php.net/advisory-032005.php
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
http://www.hardened-php.net/advisory-042005.php
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
http://www.securityfocus.com/archive/1/404047/30/30/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/404054
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/14128
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/14129
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2005/0951
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/21266
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/21270
Source: af854a3a-2127-422b-91ae-364da2661108

28 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
4.1%
89th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

the_cacti_group