CVE-2004-1736: Medium severity The Cacti Group Cacti vulnerability
Published Dec 31, 2004
·Updated
Cacti 0.8.5a allows remote attackers to gain sensitive information via an HTTP request to (1) auth.php, (2) authlogin.php, (3) authchangepassword.php, and possibly other php files, which reveal the installation path in a PHP error message.
Affected Software
1 affected component
The Cacti Group Cacti=0.8.5a
Event History
Dec 31, 2004
CVE Published
05:00 AM
Feb 26, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1736?
The severity of CVE-2004-1736 is considered moderate as it allows attackers to gain sensitive information.
2
How do I fix CVE-2004-1736?
To fix CVE-2004-1736, upgrade to a version of Cacti later than 0.8.5a that has the vulnerability patched.
3
What types of information can be exposed due to CVE-2004-1736?
CVE-2004-1736 can expose sensitive information such as the installation path through error messages in specific PHP files.
4
Which versions of Cacti are affected by CVE-2004-1736?
CVE-2004-1736 affects Cacti version 0.8.5a specifically.
5
Can I exploit CVE-2004-1736 remotely?
Yes, CVE-2004-1736 can be exploited remotely through crafted HTTP requests.