CVE-2004-1737 – RaXnet Cacti 0.6.x/0.8.x - 'Auth_Login.php' SQL Injection
https://notcve.org/view.php?id=CVE-2004-1737
16 Aug 2004 — SQL injection vulnerability in auth_login.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters. • https://www.exploit-db.com/exploits/24375 •
CVE-2002-1478
https://notcve.org/view.php?id=CVE-2002-1478
22 Apr 2003 — Cacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode. Cacti anteriores a 0.6.8 permite a atacantes ejecutar comandos arbitrarios mediante la opción "Data Input" en el modo de consola. • http://archives.neohapsis.com/archives/bugtraq/2002-09/0028.html •
CVE-2002-1477
https://notcve.org/view.php?id=CVE-2002-1477
22 Apr 2003 — graphs.php in Cacti before 0.6.8 allows remote authenticated Cacti administrators to execute arbitrary commands via shell metacharacters in the title during edit mode. graphs.php en Cacti anteriores a 0.6.8 permite a administradores ejecutar comandos arbitrarios mediante metacaractéres de shell en el título durante el modo de edición. • http://archives.neohapsis.com/archives/bugtraq/2002-09/0028.html •
CVE-2002-1479
https://notcve.org/view.php?id=CVE-2002-1479
22 Apr 2003 — Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users to modify databases as the Cacti user and possibly gain privileges. Cacti anteriores a 0.6.8 almacena un nombre de usuario y contraseña de MySQL en texto plano en config.php, que tiene permiso de lectura para todo el mundo, lo que permite a usuarios locales modificar bases de datos como el usuario Cacti y posiblemente ganar privilegios. • http://archives.neohapsis.com/archives/bugtraq/2002-09/0028.html •