CVE-2004-1737: SQL Injection
Published Aug 16, 2004
·Updated
SQL injection vulnerability in authlogin.php in Cacti 0.8.5a allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) password parameters.
Affected Software
20 affected components
The Cacti Group Cacti=0.6
The Cacti Group Cacti=0.6.1
The Cacti Group Cacti=0.6.2
The Cacti Group Cacti=0.6.3
The Cacti Group Cacti=0.6.4
The Cacti Group Cacti=0.6.5
The Cacti Group Cacti=0.6.6
The Cacti Group Cacti=0.6.7
The Cacti Group Cacti=0.6.8
The Cacti Group Cacti=0.6.8a
The Cacti Group Cacti=0.8
The Cacti Group Cacti=0.8.1
The Cacti Group Cacti=0.8.2
The Cacti Group Cacti=0.8.2a
The Cacti Group Cacti=0.8.3
The Cacti Group Cacti=0.8.3a
The Cacti Group Cacti=0.8.4
The Cacti Group Cacti=0.8.5
The Cacti Group Cacti=0.8.5a
Gentoo Linux=1.4
Remediation
Patch Available
Patch Available
Patch Available
Event History
Aug 16, 2004
CVE Published
04:00 AM
Feb 26, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1737?
CVE-2004-1737 has a medium severity level due to its potential for unauthorized SQL command execution.
2
How do I fix CVE-2004-1737?
To fix CVE-2004-1737, update Cacti to a version that is not vulnerable, specifically versions 0.8.5 or later.
3
Which Cacti versions are affected by CVE-2004-1737?
CVE-2004-1737 affects Cacti versions from 0.6 to 0.8.5a.
4
Can CVE-2004-1737 be exploited remotely?
Yes, CVE-2004-1737 can be exploited remotely by attackers using the username or password parameters.
5
What types of attacks can occur due to CVE-2004-1737?
CVE-2004-1737 can allow attackers to execute arbitrary SQL commands, potentially leading to authentication bypass.