Back to Database
Status published
High
CVE-2005-1526
PHP remote file inclusion vulnerability in config_settings.php in Cacti before...
Vulnerability Description
PHP remote file inclusion vulnerability in config_settings.php in Cacti before 0.8.6e allows remote attackers to execute arbitrary PHP code via the config[include_path] parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2005-1526
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.idefense.com/application/poi/display?id=266&type=vulnerabilities
- http://www.osvdb.org/17425
- http://distro.conectiva.com/atualizacoes/index.php?id=a&anuncio=000978
- http://www.cacti.net/release_notes_0_8_6e.php
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21119
- http://www.gentoo.org/security/en/glsa/glsa-200506-20.xml
- http://www.debian.org/security/2005/dsa-764
- http://securitytracker.com/id?1014252
- http://secunia.com/advisories/15931
- http://www.securityfocus.com/bid/14028
- http://secunia.com/advisories/15490
More from the cacti group
View All →CVE-2007-3113
Cacti 0.8.6i, and possibly other versions, allows remote authenticated users...
Medium
6.8
CVE-2007-3112
graph_image.php in Cacti 0.8.6i, and possibly other versions, allows remote...
High
7.8
CVE-2006-6799
SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv...
High
7.5
CVE-2005-2149
config.php in Cacti 0.8.6e and earlier allows remote attackers to...
Critical
10
CVE-2005-2148
Cacti 0.8.6e and earlier does not perform proper input validation...
High
7.5
Affected Vendor
the cacti group
View all reports →Affected Software
cacti
Vulnerable Versions:
0, 0.5, 0.6, 0.6.1, 0.6.2, 0.6.3, 0.6.4, 0.6.5, 0.6.6, 0.6.7, 0.6.8, 0.6.8a, 0.8, 0.8.1, 0.8.2, 0.8.2a, 0.8.3, 0.8.3a, 0.8.4, 0.8.5a
Timeline
Official Publish:
June 22nd, 2005
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.