CVE-2015-4634

Cacti < 0.8.8d - SQL Injection via graphs.php local_graph_id Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in graphs.php in Cacti before 0.8.8e allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter.

References (5)

Core 5
Core References
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2015-07/msg00052.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1032989
Various Sources x_refsource_confirm
http://www.cacti.net/release_notes_0_8_8e.php
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2015/dsa-3312
Exploit x_refsource_confirm
http://bugs.cacti.net/view.php?id=2577

Scores

EPSS 0.0218
EPSS Percentile 80.4%

Details

CWE
CWE-89
Status published
Products (1)
cacti/cacti < 0.8.8d
Published Aug 11, 2015
Tracked Since Feb 18, 2026