Vulnerability Description
SQL injection vulnerability in graphs.php in Cacti before 0.8.8e allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cacti | Cacti | <= 0.8.8d |
Related Weaknesses (CWE)
References
- http://bugs.cacti.net/view.php?id=2577Exploit
- http://lists.opensuse.org/opensuse-updates/2015-07/msg00052.html
- http://www.cacti.net/release_notes_0_8_8e.php
- http://www.debian.org/security/2015/dsa-3312
- http://www.securitytracker.com/id/1032989
- http://bugs.cacti.net/view.php?id=2577Exploit
- http://lists.opensuse.org/opensuse-updates/2015-07/msg00052.html
- http://www.cacti.net/release_notes_0_8_8e.php
- http://www.debian.org/security/2015/dsa-3312
- http://www.securitytracker.com/id/1032989
FAQ
What is CVE-2015-4634?
CVE-2015-4634 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL injection vulnerability in graphs.php in Cacti before 0.8.8e allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter.
How severe is CVE-2015-4634?
CVE-2015-4634 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-4634?
Check the references section above for vendor advisories and patch information. Affected products include: Cacti Cacti.