CyberSec.Space Logo
Back to CVE Browser

CVE-2005-2149

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0940%
EPSS Percentile35.92th
PublishedJul 6, 2005
Last ModifiedApr 16, 2026

Vulnerability Description

config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.

Affected Platforms (CPE)

πŸ“¦
The Cacti Group

Cacti

= 0.8
πŸ“¦
The Cacti Group

Cacti

= 0.8.1
πŸ“¦
The Cacti Group

Cacti

= 0.8.2
πŸ“¦
The Cacti Group

Cacti

= 0.8.2a
πŸ“¦
The Cacti Group

Cacti

= 0.8.3
πŸ“¦
The Cacti Group

Cacti

= 0.8.3a
πŸ“¦
The Cacti Group

Cacti

= 0.8.4
πŸ“¦
The Cacti Group

Cacti

= 0.8.5
πŸ“¦
The Cacti Group

Cacti

= 0.8.5a
πŸ“¦
The Cacti Group

Cacti

= 0.8.6
πŸ“¦
The Cacti Group

Cacti

= 0.8.6a
πŸ“¦
The Cacti Group

Cacti

= 0.8.6b
πŸ“¦
The Cacti Group

Cacti

= 0.8.6c
πŸ“¦
The Cacti Group

Cacti

= 0.8.6d
πŸ“¦
The Cacti Group

Cacti

= 0.8.6e

References & Advisories

Related Vulnerabilities