CVE-2015-8369: SQL Injection
Published Dec 17, 2015
·Updated
SQL injection vulnerability in include/topgraphheader.php in Cacti 0.8.8f and earlier allows remote attackers to execute arbitrary SQL commands via the rraid parameter in a properties action to graph.php.
Affected Software
1 affected component
Cacti Cacti<=0.8.8f
Event History
Dec 17, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8369?
CVE-2015-8369 is classified as a medium severity SQL injection vulnerability.
2
How do I fix CVE-2015-8369?
To fix CVE-2015-8369, upgrade Cacti to version 0.8.8g or later, which addresses this vulnerability.
3
Which versions of Cacti are affected by CVE-2015-8369?
CVE-2015-8369 affects Cacti versions up to and including 0.8.8f.
4
What type of vulnerability is CVE-2015-8369?
CVE-2015-8369 is an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
5
What components are involved in CVE-2015-8369?
CVE-2015-8369 involves the include/top_graph_header.php file and the rra_id parameter in the properties action of graph.php.