CVE-2008-0785

Cacti 0.8.6-0.8.7 - Authenticated SQL Injection via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2008-0785. PoCs published by aScii.

AI-analyzed exploit summary The exploit demonstrates SQL injection and XSS vulnerabilities in Cacti 0.8.7a and prior versions. It includes a URL-based SQLi example and a cURL command to exploit the vulnerability via POST data.

Description

Multiple SQL injection vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote authenticated users to execute arbitrary SQL commands via the (1) graph_list parameter to graph_view.php, (2) leaf_id and id parameters to tree.php, (3) local_graph_id parameter to graph_xport.php, and (4) login_username parameter to index.php/login.

Exploits (4)

exploitdb WORKING POC VERIFIED
by aScii · textwebappsphp
https://www.exploit-db.com/exploits/31159

The exploit demonstrates SQL injection and XSS vulnerabilities in Cacti 0.8.7a and prior versions. It includes a URL-based SQLi example and a cURL command to exploit the vulnerability via POST data.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Cacti 0.8.7a and prior
Auth required
Prerequisites: Valid Cacti session cookie · Access to the target Cacti instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by aScii · textwebappsphp
https://www.exploit-db.com/exploits/31160

This exploit demonstrates a SQL injection vulnerability in Cacti's graph_xport.php by injecting a single quote into the local_graph_id parameter. It requires a valid session cookie to exploit the vulnerability.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Cacti 0.8.7a and prior versions
Auth required
Prerequisites: Valid session cookie for Cacti
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by aScii · textwebappsphp
https://www.exploit-db.com/exploits/31156

The provided text describes multiple vulnerabilities in Cacti 0.8.7a and prior, including SQL injection, XSS, and HTTP response splitting. It includes a sample SQL injection payload for demonstration but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Sqli | Xss | Other
Complexity
Trivial
Reliability
Theoretical
Target: Cacti 0.8.7a and prior
No auth needed
Prerequisites: Access to the Cacti web interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by aScii · textwebappsphp
https://www.exploit-db.com/exploits/31161

This exploit demonstrates a blind SQL injection vulnerability in Cacti 0.8.7a and prior versions. It uses conditional queries to infer password characters by observing HTTP response status codes.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Cacti 0.8.7a and prior
No auth needed
Prerequisites: Network access to the target Cacti instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (19)

Core 19
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=432758
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27749
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1019414
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29242
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3657
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200803-18.xml
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28872
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2008:052
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30045
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29274
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/488013/100/0/threaded
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0540
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2008/dsa-1569
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28976
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/488018/100/0/threaded

Scores

EPSS 0.0343
EPSS Percentile 87.4%

Details

CWE
CWE-89
Status published
Products (16)
cacti/cacti 0.6.7
cacti/cacti 0.8
cacti/cacti 0.8.1
cacti/cacti 0.8.2
cacti/cacti 0.8.2a
cacti/cacti 0.8.3
cacti/cacti 0.8.3a
cacti/cacti 0.8.4
cacti/cacti 0.8.5
cacti/cacti 0.8.5a
... and 6 more
Published Feb 14, 2008
Tracked Since Feb 18, 2026