CVE-2015-4634
Cacti < 0.8.8d - SQL Injection via graphs.php local_graph_id Parameter
Title source: llmDescription
SQL injection vulnerability in graphs.php in Cacti before 0.8.8e allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter.
References (5)
Core 5
Core References
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2015-07/msg00052.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1032989
Various Sources x_refsource_confirm
http://www.cacti.net/release_notes_0_8_8e.php
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2015/dsa-3312
Exploit x_refsource_confirm
http://bugs.cacti.net/view.php?id=2577
Scores
EPSS
0.0218
EPSS Percentile
80.4%
Details
CWE
CWE-89
Status
published
Products (1)
cacti/cacti
< 0.8.8d
Published
Aug 11, 2015
Tracked Since
Feb 18, 2026