CVE-2017-1000031: SQL Injection
Published Jul 13, 2017
·Updated
SQL injection vulnerability in graphtemplatesinputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary SQL commands via the graphtemplateinputid and graphtemplateid parameters.
Affected Software
1 affected component
Cacti Cacti=0.8.8b
Event History
Jul 13, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-1000031?
CVE-2017-1000031 is classified as a critical severity vulnerability due to its potential for remote SQL injection.
2
How do I fix CVE-2017-1000031?
To fix CVE-2017-1000031, it is recommended to upgrade to a patched version of Cacti if available.
3
What software is affected by CVE-2017-1000031?
CVE-2017-1000031 specifically affects Cacti version 0.8.8b.
4
Can CVE-2017-1000031 be exploited remotely?
Yes, CVE-2017-1000031 can be exploited remotely by attackers through SQL injection.
5
What parameters are involved in CVE-2017-1000031?
The parameters involved in CVE-2017-1000031 are graph_template_input_id and graph_template_id.