CVE-2014-2709: Cacti
High severity, CVSS 7.5. EPSS: 5.1% chance of exploitation in the next 30 days.
lib/rrd.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified parameters.
Affected products
- Cacti Cacti: from 0.8.7, up to and including 0.8.7g; from 0.8.8, up to and including 0.8.8b
- Debian Debian Linux: version 7.0 only; version 8.0 only
Published 2014-04-23. Last modified 2026-06-17.