CVE-2008-0785 details multiple SQL injection vulnerabilities in Cacti versions 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k. These flaws allow remote authenticated users to execute arbitrary SQL commands through various parameters in graph_view.php, tree.php, graph_xport.php, and index.php/login. The vulnerability has a CVSS score of 7.5, indicating high severity with network-based attacks, low attack complexity, and potential for partial compromise of confidentiality, integrity, and availability. Its FAUCET Risk Score is 89/100, highlighting its significant risk. While not listed on the KEV catalog, exploit code is publicly available on ExploitDB for all identified injection points. Despite this, there is no evidence of active exploitation, and the vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.6.7CPE matchmatch criteria | cpe:2.3:a:cacti:cacti:0.6.7:*:*:*:*:*:*:* | ||
0.8CPE matchmatch criteria | cpe:2.3:a:cacti:cacti:0.8:*:*:*:*:*:*:* | ||
0.8.1CPE matchmatch criteria | cpe:2.3:a:cacti:cacti:0.8.1:*:*:*:*:*:*:* | ||
0.8.2CPE matchmatch criteria | cpe:2.3:a:cacti:cacti:0.8.2:*:*:*:*:*:*:* | ||
0.8.2aCPE matchmatch criteria | cpe:2.3:a:cacti:cacti:0.8.2a:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.