First published: Fri May 22 2015(Updated: )
SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote authenticated users to execute arbitrary SQL commands via the local_graph_id parameter, a different vulnerability than CVE-2007-6035.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti | <=0.8.6e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0916 is classified as a medium severity vulnerability due to its potential for SQL injection leading to unauthorized data access.
To fix CVE-2015-0916, upgrade Cacti to version 0.8.6f or later, which addresses this vulnerability.
CVE-2015-0916 affects users of Cacti versions prior to 0.8.6f who have authenticated access.
CVE-2015-0916 is an SQL injection vulnerability that allows attackers to execute arbitrary SQL commands.
Yes, CVE-2015-0916 can be exploited by remote authenticated users to execute arbitrary SQL commands.