First published: Fri Aug 22 2014(Updated: )
The graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a font size, related to the rrdtool commandline in lib/rrd.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti | <=0.8.8b | |
Cacti | =0.8.6e | |
Cacti | =0.8.7 | |
Cacti | =0.8.7a | |
Cacti | =0.8.7b | |
Cacti | =0.8.7c | |
Cacti | =0.8.7d | |
Cacti | =0.8.7e | |
Cacti | =0.8.7f | |
Cacti | =0.8.7g | |
Cacti | =0.8.7i | |
Cacti | =0.8.8 | |
Cacti | =0.8.8a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5261 has a high severity rating due to its potential for remote command execution.
To fix CVE-2014-5261, upgrade Cacti to version 0.8.8c or later.
CVE-2014-5261 allows attackers to execute arbitrary commands on the server via input manipulation.
CVE-2014-5261 affects Cacti versions up to and including 0.8.8b and specific older versions.
Yes, the exploitation of CVE-2014-5261 could lead to unauthorized access and potential data breaches.