Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled during graph rendering. This flaw allows attackers to execute commands on the underlying operating system with the privileges of the web server process, potentially compromising system integrity.
Metrics
Affected Vendors & Products
References
History
Sun, 31 Aug 2025 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cacti
Cacti cacti |
|
Vendors & Products |
Cacti
Cacti cacti |
Sat, 30 Aug 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled during graph rendering. This flaw allows attackers to execute commands on the underlying operating system with the privileges of the web server process, potentially compromising system integrity. | |
Title | Cacti graph_view.php RCE via graph_start Parameter Injection | |
Weaknesses | CWE-78 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-08-30T13:45:16.222Z
Reserved: 2025-08-28T18:08:00.944Z
Link: CVE-2005-10004

No data.

Status : Received
Published: 2025-08-30T14:15:32.040
Modified: 2025-08-30T14:15:32.040
Link: CVE-2005-10004

No data.

Updated: 2025-08-31T08:41:30Z