CVE-2014-5261: Code Injection
Published Aug 22, 2014
·Updated
The graph settings script (graphsettings.php) in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a font size, related to the rrdtool commandline in lib/rrd.php.
Affected Software
13 affected components
Cacti Cacti<=0.8.8b
Cacti Cacti=0.8.6e
Cacti Cacti=0.8.7
Cacti Cacti=0.8.7a
Cacti Cacti=0.8.7b
Cacti Cacti=0.8.7c
Cacti Cacti=0.8.7d
Cacti Cacti=0.8.7e
Cacti Cacti=0.8.7f
Cacti Cacti=0.8.7g
Cacti Cacti=0.8.7i
Cacti Cacti=0.8.8
Cacti Cacti=0.8.8a
Remediation
Patch Available
Event History
Aug 22, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5261?
CVE-2014-5261 has a high severity rating due to its potential for remote command execution.
2
How do I fix CVE-2014-5261?
To fix CVE-2014-5261, upgrade Cacti to version 0.8.8c or later.
3
What types of attacks are possible with CVE-2014-5261?
CVE-2014-5261 allows attackers to execute arbitrary commands on the server via input manipulation.
4
Which versions of Cacti are affected by CVE-2014-5261?
CVE-2014-5261 affects Cacti versions up to and including 0.8.8b and specific older versions.
5
Can the exploitation of CVE-2014-5261 lead to data breaches?
Yes, the exploitation of CVE-2014-5261 could lead to unauthorized access and potential data breaches.