CVE-2020-35701 PUBLISHED

An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in data_debug.php allows remote authenticated attackers to execute arbitrary SQL commands via the site_id parameter. This can lead to remote code execution.

EPSS 1.84% · 82.8th percentile

Risk Scores

EPSS Score
1.84%
82.8th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:20.04:LTScacti0, 1.2.4+ds1-2ubuntu3, 1.2.9+ds1-1ubuntu1
Ubuntu:Pro:14.04:LTScacti0.8.8b+dfsg-5ubuntu0.2+esm1, 0, 0.8.8b+dfsg-5ubuntu0.2+esm2

Timeline

References

Open in Interactive Console →