CVE-2014-4000: Code Injection
Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object, related to calling unserialize(stripslashes()).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4000?
CVE-2014-4000 is considered a significant vulnerability due to its potential for PHP object injection and remote code execution.
How do I fix CVE-2014-4000?
To fix CVE-2014-4000, update Cacti to version 1.0.0 or later, ensuring that no affected versions are in use.
Who is affected by CVE-2014-4000?
CVE-2014-4000 affects all Cacti installations prior to version 1.0.0 that allow remote authenticated users to input crafted serialized objects.
What type of attacks does CVE-2014-4000 enable?
CVE-2014-4000 enables remote authenticated users to conduct PHP object injection attacks, leading to execution of arbitrary PHP code.
What versions of Cacti are vulnerable to CVE-2014-4000?
Versions of Cacti prior to 1.0.0 are vulnerable to CVE-2014-4000.