First published: Fri Aug 22 2014(Updated: )
SQL injection vulnerability in the graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti | <=0.8.8b | |
Cacti | =0.8.6e | |
Cacti | =0.8.7 | |
Cacti | =0.8.7a | |
Cacti | =0.8.7b | |
Cacti | =0.8.7c | |
Cacti | =0.8.7d | |
Cacti | =0.8.7e | |
Cacti | =0.8.7f | |
Cacti | =0.8.7g | |
Cacti | =0.8.7i | |
Cacti | =0.8.8 | |
Cacti | =0.8.8a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5262 has a medium severity rating due to its potential to allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2014-5262, you should upgrade to a version of Cacti later than 0.8.8b.
CVE-2014-5262 affects Cacti versions 0.8.8b and earlier, including versions 0.8.6e to 0.8.8a.
CVE-2014-5262 is an SQL injection vulnerability that allows attackers to manipulate SQL queries.
Yes, CVE-2014-5262 can lead to data breaches as it allows attackers to execute arbitrary SQL commands, potentially accessing sensitive data.