Skip to main content
HIGH

CVE-2005-10004

CVSS v3

8.8

HIGH

EPSS Score

2.0 %

exploit probability, as of 2026-10-03

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled during graph rendering. This flaw allows attackers to execute commands on the underlying operating system with the privileges of the web server process, potentially compromising system integrity.

Technical details

Published
2025-08-30

Frequently asked questions

What is CVE-2005-10004?

Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled during graph rendering. This flaw allows attackers to execute commands on the underlying operating system with the privileges of the web server process, potentially compromising system integrity.

Is CVE-2005-10004 actively exploited?

Active exploitation of CVE-2005-10004 has not been confirmed. Its EPSS score was 2.0% on 2026-10-03, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2005-10004?

CVE-2005-10004 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2005-10004 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 50 free checks/month · Free API key

Other 2005 vulnerabilities worth triaging

Ranked by exploit probability (EPSS).