Vulnerabilities > CVE-2004-1736 - Unspecified vulnerability in the Cacti Group Cacti 0.8.5A

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
the-cacti-group

Summary

Cacti 0.8.5a allows remote attackers to gain sensitive information via an HTTP request to (1) auth.php, (2) auth_login.php, (3) auth_changepassword.php, and possibly other php files, which reveal the installation path in a PHP error message.

Vulnerable Configurations

Part Description Count
Application
The_Cacti_Group
1