← Vulnerability feed

Vulnerability record · CVE-2005-2148 · published 6 July 2005

CVE-2005-2148: The cacti group cacti vulnerability

TThe Cacti Group · Cacti

Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitrary commands or SQL by sending a legitimate value in a POST request or cookie, then specifying the attack string in the URL, which causes the get_request_var function to return the wrong value in the $_REQUEST variable, which is cleansed while the original malicious $_GET value remains unmodified, as demonstrated in (1) graph_image.php and (2) graph.php.

7.5 CVSS 2.0 High EPSS 3.4% · top 11.6%
7.5CVSS 2.0 base score
3.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
28References
16 Jun 2026Last modified by NVD

Description

Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitrary commands or SQL by sending a legitimate value in a POST request or cookie, then specifying the attack string in the URL, which causes the get_request_var function to return the wrong value in the $_REQUEST variable, which is cleansed while the original malicious $_GET value remains unmodified, as demonstrated in (1) graph_image.php and (2) graph.php.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/15490
http://securitytracker.com/id?1014361
http://sourceforge.net/mailarchive/forum.php?forum_id=10360&max_rows=25&style=flat&viewmonth=200507&viewday=1 Patch
http://www.cacti.net/downloads/patches/0.8.6e/cacti-0.8.6f_security.patch Patch
http://www.debian.org/security/2005/dsa-764
http://www.hardened-php.net/advisory-032005.php PatchVendor Advisory
http://www.hardened-php.net/advisory-042005.php Patch
http://www.securityfocus.com/archive/1/404047/30/30/threaded
http://www.securityfocus.com/archive/1/404054
http://www.securityfocus.com/bid/14128
http://www.securityfocus.com/bid/14129
http://www.vupen.com/english/advisories/2005/0951
https://exchange.xforce.ibmcloud.com/vulnerabilities/21266
https://exchange.xforce.ibmcloud.com/vulnerabilities/21270
http://secunia.com/advisories/15490
http://securitytracker.com/id?1014361
http://sourceforge.net/mailarchive/forum.php?forum_id=10360&max_rows=25&style=flat&viewmonth=200507&viewday=1 Patch
http://www.cacti.net/downloads/patches/0.8.6e/cacti-0.8.6f_security.patch Patch
http://www.debian.org/security/2005/dsa-764
http://www.hardened-php.net/advisory-032005.php PatchVendor Advisory
http://www.hardened-php.net/advisory-042005.php Patch
http://www.securityfocus.com/archive/1/404047/30/30/threaded
http://www.securityfocus.com/archive/1/404054
http://www.securityfocus.com/bid/14128
http://www.securityfocus.com/bid/14129
http://www.vupen.com/english/advisories/2005/0951
https://exchange.xforce.ibmcloud.com/vulnerabilities/21266
https://exchange.xforce.ibmcloud.com/vulnerabilities/21270

Track CVE-2005-2148 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-2149The cacti group cacti vulnerabilityconfig.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges …EPSS 2.3%10.0CVE-2002-1478The cacti group cacti vulnerabilityCacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode.EPSS 2.5%7.8CVE-2007-3112The cacti group cacti vulnerabilitygraph_image.php in Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a …EPSS 2.4%7.5CVE-2006-6799The cacti group cacti vulnerabilitySQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL command…EPSS 2.6%7.5CVE-2006-0146John lim adodb sql injection vulnerabilityThe server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) …EPSS 13%7.5CVE-2006-0147John lim adodb vulnerabilityDynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis…EPSS 13%7.5CVE-2005-1525The cacti group cacti vulnerabilitySQL injection vulnerability in config_settings.php for Cacti before 0.8.6e allows remote attackers to execute arbitrary SQL commands via the id param…EPSS 1.9%7.5CVE-2005-1526The cacti group cacti vulnerabilityPHP remote file inclusion vulnerability in config_settings.php in Cacti before 0.8.6e allows remote attackers to execute arbitrary PHP code via the c…EPSS 17%

Source: NIST National Vulnerability Database (record CVE-2005-2148), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.