Cacti Multiple SQL Injection Vulnerabilities



Cacti is prone to multiple SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query.

Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

Information

Bugtraq ID: 75972
Class: Input Validation Error
CVE: CVE-2015-4634

Remote: Yes
Local: No
Published: Jul 21 2015 12:00AM
Updated: Apr 12 2019 08:00PM
Credit: Alessandro Ghedini
Vulnerable: Planet Technology WSW-2401 0.8.6 h
Planet Technology WSW-2401 0.8.6 g
Cacti Spine 0.8.7g
Cacti Cacti 0.8.7
Cacti Cacti 0.8.6 f
Cacti Cacti 0.8.6 c
Cacti Cacti 0.8.5 a
Cacti Cacti 0.8.5
Cacti Cacti 0.8.4
Cacti Cacti 0.8.3 a
Cacti Cacti 0.8.3
Cacti Cacti 0.8.2 a
Cacti Cacti 0.8.2
Cacti Cacti 0.8.1
Cacti Cacti 0.8
Cacti Cacti 0.6.7
Cacti Cacti 0.8.8d
Cacti Cacti 0.8.8c
Cacti Cacti 0.8.8b
Cacti Cacti 0.8.8a
Cacti Cacti 0.8.8
Cacti Cacti 0.8.7i
Cacti Cacti 0.8.7h
Cacti Cacti 0.8.7g
Cacti Cacti 0.8.7f
Cacti Cacti 0.8.7e
Cacti Cacti 0.8.7d
Cacti Cacti 0.8.7c
Cacti Cacti 0.8.7b
Cacti Cacti 0.8.7a
Cacti Cacti 0.8.6k
Cacti Cacti 0.8.6j
Cacti Cacti 0.8.6i
Cacti Cacti 0.8.6F
Cacti Cacti 0.8.6E


Not Vulnerable: Cacti Cacti 0.8.8e


Exploit


An attacker can exploit these issues using a web browser.


Related Posts