CVE-2006-6799

Cacti <0.8.6i - SQL Injection

Title source: llm

Description

SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL commands via the (1) second or (2) third arguments to cmd.php. NOTE: this issue can be leveraged to execute arbitrary commands since the SQL query results are later used in the polling_items array and popen function.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/3029

Scores

EPSS 0.0290
EPSS Percentile 86.4%

Details

Status published
Products (1)
the_cacti_group/cacti < 0.8.6i
Published Dec 28, 2006
Tracked Since Feb 18, 2026