First published: Tue Apr 22 2003(Updated: )
graphs.php in Cacti before 0.6.8 allows remote authenticated Cacti administrators to execute arbitrary commands via shell metacharacters in the title during edit mode.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti | =0.5 | |
Cacti | =0.6.7 | |
Cacti | =0.6.4 | |
Cacti | =0.6.1 | |
Cacti | =0.6 | |
Cacti | =0.6.6 | |
Cacti | =0.6.5 | |
Cacti | =0.6.3 | |
Cacti | =0.6.8 | |
Cacti | =0.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1477 is considered a critical vulnerability as it allows remote authenticated Cacti administrators to execute arbitrary commands.
To fix CVE-2002-1477, upgrade Cacti to version 0.6.8 or later.
CVE-2002-1477 affects Cacti versions up to 0.6.7, including versions 0.5, 0.6.1 through 0.6.7.
Yes, exploitation of CVE-2002-1477 requires remote authenticated access to Cacti.
CVE-2002-1477 allows attackers to execute arbitrary commands on the server through manipulated input.