CVE-2005-10004 Affecting cacti package, versions <0.8.6d-1


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
1.91% (78th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ECHOLATEST-CACTI-18610633
  • published11 Aug 2026
  • disclosed30 Aug 2025

Introduced: 30 Aug 2025

CVE-2005-10004  (opens in a new tab)

How to fix?

Upgrade Echo:latest cacti to version 0.8.6d-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream cacti package and not the cacti package as distributed by Echo. See How to fix? for Echo:latest relevant fixed versions and status.

Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled during graph rendering. This flaw allows attackers to execute commands on the underlying operating system with the privileges of the web server process, potentially compromising system integrity.

CVSS Base Scores

version 3.1