← Vulnerability feed

Vulnerability record · CVE-2006-6799 · published 28 December 2006

CVE-2006-6799: The cacti group cacti vulnerability

TThe Cacti Group · Cacti

SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL commands via the (1) second or (2) third arguments to cmd.php. NOTE: this issue can be leveraged to execute arbitrary commands since the SQL query results are later used in the polling_items array and popen function.

7.5 CVSS 2.0 High EPSS 2.6% · top 15.3%
7.5CVSS 2.0 base score
2.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
32References
16 Jun 2026Last modified by NVD

Description

SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL commands via the (1) second or (2) third arguments to cmd.php. NOTE: this issue can be leveraged to execute arbitrary commands since the SQL query results are later used in the polling_items array and popen function.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/23528 Vendor Advisory
http://secunia.com/advisories/23665
http://secunia.com/advisories/23917
http://secunia.com/advisories/23941
http://security.gentoo.org/glsa/glsa-200701-23.xml
http://securitytracker.com/id?1017451
http://www.cacti.net/release_notes_0_8_6j.php
http://www.debian.org/security/2007/dsa-1250
http://www.mandriva.com/security/advisories?name=MDKSA-2007:015
http://www.novell.com/linux/security/advisories/2007_07_cacti.html
http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.001.html
http://www.securityfocus.com/archive/1/457290/100/0/threaded
http://www.securityfocus.com/bid/21799
http://www.vupen.com/english/advisories/2006/5193
https://exchange.xforce.ibmcloud.com/vulnerabilities/31177
https://www.exploit-db.com/exploits/3029
http://secunia.com/advisories/23528 Vendor Advisory
http://secunia.com/advisories/23665
http://secunia.com/advisories/23917
http://secunia.com/advisories/23941
http://security.gentoo.org/glsa/glsa-200701-23.xml
http://securitytracker.com/id?1017451
http://www.cacti.net/release_notes_0_8_6j.php
http://www.debian.org/security/2007/dsa-1250
http://www.mandriva.com/security/advisories?name=MDKSA-2007:015
http://www.novell.com/linux/security/advisories/2007_07_cacti.html
http://www.openpkg.com/security/advisories/OpenPKG-SA-2007.001.html
http://www.securityfocus.com/archive/1/457290/100/0/threaded
http://www.securityfocus.com/bid/21799
http://www.vupen.com/english/advisories/2006/5193
https://exchange.xforce.ibmcloud.com/vulnerabilities/31177
https://www.exploit-db.com/exploits/3029

Track CVE-2006-6799 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-2149The cacti group cacti vulnerabilityconfig.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges …EPSS 2.3%10.0CVE-2002-1478The cacti group cacti vulnerabilityCacti before 0.6.8 allows attackers to execute arbitrary commands via the "Data Input" option in console mode.EPSS 2.5%7.8CVE-2007-3112The cacti group cacti vulnerabilitygraph_image.php in Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a …EPSS 2.4%7.5CVE-2006-0146John lim adodb sql injection vulnerabilityThe server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) …EPSS 13%7.5CVE-2006-0147John lim adodb vulnerabilityDynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis…EPSS 13%7.5CVE-2005-2148The cacti group cacti vulnerabilityCacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitra…EPSS 3.4%7.5CVE-2005-1525The cacti group cacti vulnerabilitySQL injection vulnerability in config_settings.php for Cacti before 0.8.6e allows remote attackers to execute arbitrary SQL commands via the id param…EPSS 1.9%7.5CVE-2005-1526The cacti group cacti vulnerabilityPHP remote file inclusion vulnerability in config_settings.php in Cacti before 0.8.6e allows remote attackers to execute arbitrary PHP code via the c…EPSS 17%

Source: NIST National Vulnerability Database (record CVE-2006-6799), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.