Cacti 0.8.5a allows remote attackers to gain sensitive information via an HTTP request to (1) auth.php, (2) authlogin.php, (3) authchangepassword.php, and possibly other php files, which reveal the installation path in a PHP error message.
{ "urgency": "not yet assigned" }
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2004-1736.json"