CVE-2009-4112

Cacti <0.8.7e - Privilege Escalation

Title source: llm
STIX 2.1

Description

Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux - Get Memory Usage" setting to contain arbitrary commands.

Exploits (1)

exploitdb WORKING POC VERIFIED
by MustLive · textwebappsphp
https://www.exploit-db.com/exploits/33377

References (10)

Core 10
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/11/26/1
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/508129/100/0/threaded
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2009/11/30/2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/54473
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/37137

Scores

EPSS 0.0799
EPSS Percentile 92.1%

Details

CWE
CWE-264
Status published
Products (16)
cacti/cacti 0.6.7
cacti/cacti 0.8
cacti/cacti 0.8.1
cacti/cacti 0.8.2
cacti/cacti 0.8.2a
cacti/cacti 0.8.3
cacti/cacti 0.8.3a
cacti/cacti 0.8.4
cacti/cacti 0.8.5
cacti/cacti 0.8.5a
... and 6 more
Published Nov 30, 2009
Tracked Since Feb 18, 2026