CVE-2007-6035
published 2007-11-20CVE-2007-6035: SQL injection vulnerability in graph.php in Cacti before 0.8.7a allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter.
PriorityP338high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.80%
76.2th percentile
SQL injection vulnerability in graph.php in Cacti before 0.8.7a allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cacti | cacti | <= 0.8.7 | — |
| cacti | cacti | <= 0.8.6e | — |
| cacti | cacti | >= 0 < 0.8.6f-1 | 0.8.6f-1 |
| cacti | cacti | >= 0 < 0.8.7a-1 | 0.8.7a-1 |
| cacti | cacti | >= 0 < 0.8.6f-1 | 0.8.6f-1 |
| cacti | cacti | >= 0 < 0.8.7a-1 | 0.8.7a-1 |
| cacti | cacti | >= 0 < 0.8.6f-1 | 0.8.6f-1 |
| cacti | cacti | >= 0 < 0.8.7a-1 | 0.8.7a-1 |
| cacti | cacti | >= 0 < 0.8.6f-1 | 0.8.6f-1 |
| cacti | cacti | >= 0 < 0.8.7a-1 | 0.8.7a-1 |
| debian | cacti | < cacti 0.8.7a-1 (bookworm) | cacti 0.8.7a-1 (bookworm) |
| debian | cacti | < cacti 0.8.6f-1 (bookworm) | cacti 0.8.6f-1 (bookworm) |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xqwx-r7c6-p379: SQL injection vulnerability in graph
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2015-0916 [HIGH] CWE-89 GHSA-xqwx-r7c6-p379: SQL injection vulnerability in graph
SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote authenticated users to execute arbitrary SQL commands via the local_graph_id parameter, a different vulnerability than CVE-2007-6035.
GHSA
GHSA-2p92-ff6g-jxxw: SQL injection vulnerability in graph
ghsa_unreviewed·2022-05-01
CVE-2007-6035 [HIGH] CWE-89 GHSA-2p92-ff6g-jxxw: SQL injection vulnerability in graph
SQL injection vulnerability in graph.php in Cacti before 0.8.7a allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter.
OSV
CVE-2015-0916: SQL injection vulnerability in graph
osv·2015-05-22·CVSS 7.5
CVE-2015-0916 [HIGH] CVE-2015-0916: SQL injection vulnerability in graph
SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote authenticated users to execute arbitrary SQL commands via the local_graph_id parameter, a different vulnerability than CVE-2007-6035.
OSV
CVE-2007-6035: SQL injection vulnerability in graph
osv·2007-11-20·CVSS 7.5
CVE-2007-6035 [HIGH] CVE-2007-6035: SQL injection vulnerability in graph
SQL injection vulnerability in graph.php in Cacti before 0.8.7a allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter.
Debian
CVE-2015-0916: cacti - SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote au...
vendor_debian·2015·CVSS 7.5
CVE-2015-0916 [HIGH] CVE-2015-0916: cacti - SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote au...
SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote authenticated users to execute arbitrary SQL commands via the local_graph_id parameter, a different vulnerability than CVE-2007-6035.
Scope: local
bookworm: resolved (fixed in 0.8.6f-1)
bullseye: resolved (fixed in 0.8.6f-1)
forky: resolved (fixed in 0.8.6f-1)
sid: resolved (fixed in 0.8.6f-1)
trixie: resolved (fixed in 0.8.6f-1)
Red Hat
cacti SQL injection vulnerability
vendor_redhat·2007-11-17·CVSS 7.5
CVE-2007-6035 [HIGH] cacti SQL injection vulnerability
cacti SQL injection vulnerability
SQL injection vulnerability in graph.php in Cacti before 0.8.7a allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter.
Debian
CVE-2007-6035: cacti - SQL injection vulnerability in graph.php in Cacti before 0.8.7a allows remote at...
vendor_debian·2007·CVSS 7.5
CVE-2007-6035 [HIGH] CVE-2007-6035: cacti - SQL injection vulnerability in graph.php in Cacti before 0.8.7a allows remote at...
SQL injection vulnerability in graph.php in Cacti before 0.8.7a allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter.
Scope: local
bookworm: resolved (fixed in 0.8.7a-1)
bullseye: resolved (fixed in 0.8.7a-1)
forky: resolved (fixed in 0.8.7a-1)
sid: resolved (fixed in 0.8.7a-1)
trixie: resolved (fixed in 0.8.7a-1)
No detection rules found.
No public exploits indexed.
http://bugs.gentoo.org/show_bug.cgi?id=199509http://secunia.com/advisories/27719http://secunia.com/advisories/27745http://secunia.com/advisories/27756http://secunia.com/advisories/27891http://secunia.com/advisories/27950http://security.gentoo.org/glsa/glsa-200712-02.xmlhttp://www.cacti.net/release_notes_0_8_7a.phphttp://www.debian.org/security/2007/dsa-1418http://www.mandriva.com/security/advisories?name=MDKSA-2007:231http://www.novell.com/linux/security/advisories/2007_24_sr.htmlhttp://www.securityfocus.com/bid/26487http://www.securitytracker.com/id?1018982http://www.vupen.com/english/advisories/2007/3911https://exchange.xforce.ibmcloud.com/vulnerabilities/38559https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00794.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=199509http://secunia.com/advisories/27719http://secunia.com/advisories/27745http://secunia.com/advisories/27756http://secunia.com/advisories/27891http://secunia.com/advisories/27950http://security.gentoo.org/glsa/glsa-200712-02.xmlhttp://www.cacti.net/release_notes_0_8_7a.phphttp://www.debian.org/security/2007/dsa-1418http://www.mandriva.com/security/advisories?name=MDKSA-2007:231http://www.novell.com/linux/security/advisories/2007_24_sr.htmlhttp://www.securityfocus.com/bid/26487http://www.securitytracker.com/id?1018982http://www.vupen.com/english/advisories/2007/3911https://exchange.xforce.ibmcloud.com/vulnerabilities/38559https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00794.html
2007-11-20
Published