Code Injection in Cacti - CVE-2013-1435
Published: August 23, 2013 / Updated: July 28, 2020
Vulnerability identifier: #VU32633
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-1435
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
(1) snmp.php and (2) rrd.php in Cacti before 0.8.8b allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.
Affected software
Cacti
Amazon Linux AMI
Fedora
cacti (Alpine package)
cacti
Amazon Linux AMI
Fedora
cacti (Alpine package)
cacti
How to mitigate CVE-2013-1435
Install update from vendor's website.
cacti (Alpine package) - update to 0.8.8b-r0
cacti - addressed in versions 0.8.8b-1.el5, 0.8.8b-1.el6
cacti - addressed in versions 0.8.8b-1.el5, 0.8.8b-1.el6
External References
- http://forums.cacti.net/viewtopic.php?f=21&t=50593
- http://lists.opensuse.org/opensuse-updates/2013-08/msg00053.html
- http://secunia.com/advisories/54181
- http://secunia.com/advisories/54386
- http://svn.cacti.net/viewvc?view=rev&revision=7392
- http://svn.cacti.net/viewvc?view=rev&revision=7393
- http://www.debian.org/security/2012/dsa-2739
- http://www.openwall.com/lists/oss-security/2013/08/07/15