CVE-2014-4000
high
CVSS v3
8.8
CVSS v2
6.5
VIR risk
8.8
Description
Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object, related to calling unserialize(stripslashes()).
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-4000
Vendor advisory: cve@mitre.org — https://www.cacti.net/release_notes_1_0_0.php
Vendor advisory: cve@mitre.org — https://forums.cacti.net/viewtopic.php?f=4&t=56794
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 0.8.8e+ds1-1 |
| debian | bullseye | fixed | 0.8.8e+ds1-1 |
| debian | forky | fixed | 0.8.8e+ds1-1 |
| debian | sid | fixed | 0.8.8e+ds1-1 |
| debian | trixie | fixed | 0.8.8e+ds1-1 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| cacti | cacti | {"endExcluding":"1.0.0"} | 1.0.0 |
References
CWEs
CWE-94
Verify integrity in audit chain (admin only). AS-IS.