CVE-2015-0916
Cacti < 0.8.6f - Authenticated SQL Injection via local_graph_id Parameter
Title source: llmDescription
SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote authenticated users to execute arbitrary SQL commands via the local_graph_id parameter, a different vulnerability than CVE-2007-6035.
References (3)
Core 3
Core References
Patch, Vendor Advisory x_refsource_misc
http://www.cacti.net/release_notes_0_8_6f.php
Vendor Advisory third-party-advisory
x_refsource_jvndb
http://jvndb.jvn.jp/jvndb/JVNDB-2015-000064
Vendor Advisory third-party-advisory
x_refsource_jvn
http://jvn.jp/en/jp/JVN18957556/index.html
Scores
EPSS
0.0108
EPSS Percentile
61.7%
Details
CWE
CWE-89
Status
published
Products (1)
cacti/cacti
< 0.8.6e
Published
May 22, 2015
Tracked Since
Feb 18, 2026