CVE-2002-1479
Cacti before 0.6.8 stores a MySQL username and password in plaintext in config.php, which has world-readable permissions, which allows local users to modify databases as the Cacti user and possibly gain privileges.
Scoring
- CVSS base score
- 0
- EPSS probability
- 0.12%
- Published
- 2004-09-01
- Last modified
- 2026-03-16
Affected products
- n/a n/a