CVE-2020-7058

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
15/01/2020
Last modified:
04/08/2024

Description

data_input.php in Cacti 1.2.8 allows remote code execution via a crafted Input String to Data Collection -> Data Input Methods -> Unix -> Ping Host. NOTE: the vendor has stated "This is a false alarm.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cacti:cacti:1.2.8:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools