First published: Wed Jun 17 2015(Updated: )
SQL injection vulnerability in the get_hash_graph_template function in lib/functions.php in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via the graph_template_id parameter to graph_templates.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti | <=0.8.8c | |
Fedora | =22 | |
Fedora | =23 | |
Fedora | =24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2015-4454 is considered high due to the potential for remote SQL execution.
Fix CVE-2015-4454 by upgrading to Cacti version 0.8.8d or later.
CVE-2015-4454 affects Cacti versions prior to 0.8.8d, including versions up to 0.8.8c.
Yes, CVE-2015-4454 can be exploited remotely by sending specially crafted requests to the web application.
CVE-2015-4454 is an SQL injection vulnerability that allows arbitrary SQL commands to be executed.