CVE-2005-2149
CRITICAL
10.0
CVSS Severity Score
Vulnerability Description
config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.
Affected Platforms (CPE)
📦
The Cacti Group
Cacti
= 0.8📦
The Cacti Group
Cacti
= 0.8.1📦
The Cacti Group
Cacti
= 0.8.2📦
The Cacti Group
Cacti
= 0.8.2a📦
The Cacti Group
Cacti
= 0.8.3📦
The Cacti Group
Cacti
= 0.8.3a📦
The Cacti Group
Cacti
= 0.8.4📦
The Cacti Group
Cacti
= 0.8.5📦
The Cacti Group
Cacti
= 0.8.5a📦
The Cacti Group
Cacti
= 0.8.6📦
The Cacti Group
Cacti
= 0.8.6a📦
The Cacti Group
Cacti
= 0.8.6b📦
The Cacti Group
Cacti
= 0.8.6c📦
The Cacti Group
Cacti
= 0.8.6d📦
The Cacti Group
