CVE-2015-4454: SQL Injection
Published Jun 17, 2015
·Updated
SQL injection vulnerability in the gethashgraphtemplate function in lib/functions.php in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via the graphtemplateid parameter to graphtemplates.php.
Affected Software
4 affected components
Cacti<=0.8.8c
fedoraproject fedora=22
fedoraproject fedora=23
fedoraproject fedora=24
Remediation
Patch Available
Event History
Jun 17, 2015
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4454?
The severity of CVE-2015-4454 is considered high due to the potential for remote SQL execution.
2
How do I fix CVE-2015-4454?
Fix CVE-2015-4454 by upgrading to Cacti version 0.8.8d or later.
3
What are the affected versions in CVE-2015-4454?
CVE-2015-4454 affects Cacti versions prior to 0.8.8d, including versions up to 0.8.8c.
4
Can CVE-2015-4454 be exploited remotely?
Yes, CVE-2015-4454 can be exploited remotely by sending specially crafted requests to the web application.
5
What type of vulnerability is CVE-2015-4454?
CVE-2015-4454 is an SQL injection vulnerability that allows arbitrary SQL commands to be executed.