HTTP: Cacti RDD Local Scripts

This signature detects attempts to exploit a known vulnerability against Cacti RDD. A successful attack can lead to arbitrary code execution.

Extended Description

Cacti is prone to a remote command-execution vulnerability because the application fails to properly sanitize user-supplied input to the 'cmd.php' script. Exploiting this issue allows attackers to execute arbitrary commands in the context of the server. A successful exploit could facilitate the compromise of an affected computer; other attacks are also possible. Cacti 0.8.6i and prior versions are reportedly affected.

Affected Products

Openpkg openpkg

Short Name
HTTP:PHP:CACTI-RDD-LOCAL-SCRIPT
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
CVE-2006-6799 Cacti Local RDD Scripts bid:21799
Release Date
03/08/2007
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Cacti

Suse

Gentoo

Openpkg

Mandriva

Debian

CVSS Score

7.5

Found a potential security threat?