Vulnerability Name:

CVE-2006-6799 (CCN-31177)

Assigned:2006-12-27
Published:2006-12-27
Updated:2018-10-17
Summary:SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL commands via the (1) second or (2) third arguments to cmd.php.
Note: this issue can be leveraged to execute arbitrary commands since the SQL query results are later used in the polling_items array and popen function.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
6.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
6.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Data Manipulation
References:Source: MITRE
Type: CNA
CVE-2006-6799

Source: CCN
Type: SA23528
Cacti Command Execution and SQL Injection Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
23528

Source: SECUNIA
Type: UNKNOWN
23665

Source: SECUNIA
Type: UNKNOWN
23917

Source: SECUNIA
Type: UNKNOWN
23941

Source: GENTOO
Type: UNKNOWN
GLSA-200701-23

Source: CCN
Type: SECTRACK ID: 1017451
Cacti `cmd.php` Lets Remote Users Inject SQL Commands

Source: SECTRACK
Type: UNKNOWN
1017451

Source: CCN
Type: Cacti Web site
Release Notes - 0.8.6j

Source: CONFIRM
Type: UNKNOWN
http://www.cacti.net/release_notes_0_8_6j.php

Source: DEBIAN
Type: UNKNOWN
DSA-1250

Source: DEBIAN
Type: DSA-1250
cacti -- missing input sanitising

Source: CCN
Type: GLSA-200701-23
Cacti: Command execution and SQL injection

Source: MANDRIVA
Type: UNKNOWN
MDKSA-2007:015

Source: SUSE
Type: UNKNOWN
SUSE-SA:2007:007

Source: CCN
Type: OpenPKG-SA-2007.001
Cacti

Source: OPENPKG
Type: UNKNOWN
OpenPKG-SA-2007.001

Source: CCN
Type: OSVDB ID: 31468
Cacti cmd.php Multiple Parameter SQL Injection Arbitrary Command Execution

Source: BUGTRAQ
Type: UNKNOWN
20070118 Re: FW: [cacti-announce] Cacti 0.8.6j Released

Source: BID
Type: UNKNOWN
21799

Source: CCN
Type: BID-21799
Cacti CMD.PHP Remote Command Execution Vulnerability

Source: VUPEN
Type: UNKNOWN
ADV-2006-5193

Source: XF
Type: UNKNOWN
cacti-cmd-sql-injection(31177)

Source: XF
Type: UNKNOWN
cacti-cmd-sql-injection(31177)

Source: EXPLOIT-DB
Type: UNKNOWN
3029

Source: SUSE
Type: SUSE-SA:2007:007
cacti command injection

Vulnerable Configuration:Configuration 1:
  • cpe:/a:the_cacti_group:cacti:*:*:*:*:*:*:*:* (Version <= 0.8.6i)

  • Configuration CCN 1:
  • cpe:/a:cacti:cacti:0.8.6i:*:*:*:*:*:*:*
  • AND
  • cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:3.1:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:10.0::oss:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:10.1::personal:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:4.0::x86_64:*:*:*:*:*
  • OR cpe:/o:opensuse:opensuse:10.2:*:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux:9.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20066799
    V
    CVE-2006-6799
    2022-06-30
    oval:org.opensuse.security:def:112039
    P
    cacti-1.2.18-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:105594
    P
    cacti-1.2.18-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.debian:def:1250
    V
    missing input sanitising
    2007-01-17
    BACK
    the_cacti_group cacti *
    cacti cacti 0.8.6i
    gentoo linux *
    debian debian linux 3.1
    suse suse linux 10.0
    suse suse linux 10.1
    mandrakesoft mandrake linux corporate server 4.0
    mandrakesoft mandrake linux corporate server 4.0
    novell opensuse 10.2
    suse suse linux 9.3