← Vulnerability feed

Vulnerability record · CVE-2005-1526 · published 22 June 2005

CVE-2005-1526: The cacti group cacti vulnerability

TThe Cacti Group · Cacti

PHP remote file inclusion vulnerability in config_settings.php in Cacti before 0.8.6e allows remote attackers to execute arbitrary PHP code via the config[include_path] parameter.

7.5 CVSS 2.0 High EPSS 17% · top 3.1%
7.5CVSS 2.0 base score
17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
22References
16 Jun 2026Last modified by NVD

Description

PHP remote file inclusion vulnerability in config_settings.php in Cacti before 0.8.6e allows remote attackers to execute arbitrary PHP code via the config[include_path] parameter.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-1526 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-2149The cacti group cacti vulnerabilityconfig.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges …EPSS 2.3%10.0CVE-2002-1478The cacti group cacti vulnerabilityCacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode.EPSS 2.5%7.8CVE-2007-3112The cacti group cacti vulnerabilitygraph_image.php in Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a …EPSS 2.4%7.5CVE-2006-6799The cacti group cacti vulnerabilitySQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL command…EPSS 2.6%7.5CVE-2006-0146John lim adodb sql injection vulnerabilityThe server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) …EPSS 13%7.5CVE-2006-0147John lim adodb vulnerabilityDynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis…EPSS 13%7.5CVE-2005-2148The cacti group cacti vulnerabilityCacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitra…EPSS 3.4%7.5CVE-2005-1525The cacti group cacti vulnerabilitySQL injection vulnerability in config_settings.php for Cacti before 0.8.6e allows remote attackers to execute arbitrary SQL commands via the id param…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2005-1526), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.