CVE-2013-1434: Cacti

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

Multiple SQL injection vulnerabilities in (1) api_poller.php and (2) utility.php in Cacti before 0.8.8b allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

Affected products

  • Cacti Cacti: up to and including 0.8.8a; version 0.8.5 only; version 0.8.5a only; version 0.8.6 only; version 0.8.6a only; version 0.8.6b only; …

Published 2013-08-23. Last modified 2026-06-16.