CVE-2010-2092
published 2010-05-27CVE-2010-2092: SQL injection vulnerability in graph.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via a crafted rra_id parameter…
PriorityP343high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.37%
69.1th percentile
SQL injection vulnerability in graph.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via a crafted rra_id parameter in a GET request in conjunction with a valid rra_id value in a POST request or a cookie, which causes the POST or cookie value to bypass the validation routine, but inserts the $_GET value into the resulting query.
Affected
42 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cacti | cacti | <= 0.8.7e | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
| cacti | cacti | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
cacti: graph.php rra_id SQL injection vulnerability (MOPS-2010-023)
vendor_redhat·2010-05-20·CVSS 7.5
CVE-2010-2092 [HIGH] cacti: graph.php rra_id SQL injection vulnerability (MOPS-2010-023)
cacti: graph.php rra_id SQL injection vulnerability (MOPS-2010-023)
SQL injection vulnerability in graph.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via a crafted rra_id parameter in a GET request in conjunction with a valid rra_id value in a POST request or a cookie, which causes the POST or cookie value to bypass the validation routine, but inserts the $_GET value into the resulting query.
Debian
CVE-2010-2092: cacti - SQL injection vulnerability in graph.php in Cacti 0.8.7e and earlier allows remo...
vendor_debian·2010·CVSS 7.5
CVE-2010-2092 [HIGH] CVE-2010-2092: cacti - SQL injection vulnerability in graph.php in Cacti 0.8.7e and earlier allows remo...
SQL injection vulnerability in graph.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via a crafted rra_id parameter in a GET request in conjunction with a valid rra_id value in a POST request or a cookie, which causes the POST or cookie value to bypass the validation routine, but inserts the $_GET value into the resulting query.
Scope: local
bookworm: resolved (fixed in 0.8.7e-4)
bullseye: resolved (fixed in 0.8.7e-4)
forky: resolved (fixed in 0.8.7e-4)
sid: resolved (fixed in 0.8.7e-4)
trixie: resolved (fixed in 0.8.7e-4)
GHSA
GHSA-4j37-prg9-64vh: SQL injection vulnerability in graph
ghsa_unreviewed·2022-05-17
CVE-2010-2092 [HIGH] CWE-89 GHSA-4j37-prg9-64vh: SQL injection vulnerability in graph
SQL injection vulnerability in graph.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via a crafted rra_id parameter in a GET request in conjunction with a valid rra_id value in a POST request or a cookie, which causes the POST or cookie value to bypass the validation routine, but inserts the $_GET value into the resulting query.
OSV
CVE-2010-2092: SQL injection vulnerability in graph
osv·2010-05-27·CVSS 7.5
CVE-2010-2092 [HIGH] CVE-2010-2092: SQL injection vulnerability in graph
SQL injection vulnerability in graph.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via a crafted rra_id parameter in a GET request in conjunction with a valid rra_id value in a POST request or a cookie, which causes the POST or cookie value to bypass the validation routine, but inserts the $_GET value into the resulting query.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-2092 cacti: graph.php rra_id SQL injection vulnerability (MOPS-2010-023)
bugzilla·2010-06-29·CVSS 7.5
CVE-2010-2092 [HIGH] CVE-2010-2092 cacti: graph.php rra_id SQL injection vulnerability (MOPS-2010-023)
CVE-2010-2092 cacti: graph.php rra_id SQL injection vulnerability (MOPS-2010-023)
SQL injection vulnerability in graph.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via the rra_id parameter in a GET request in conjunction with a valid rra_id value in a POST request or a cookie, which bypasses the validation routine.
References:
http://php-security.org/2010/05/13/mops-2010-023-cacti-graph-viewer-sql-injection-vulnerability/index.html
http://www.cacti.net/release_notes_0_8_7f.php
Upstream commit:
http://svn.cacti.net/viewvc?view=rev&revision=5920
Discussion:
Guest user privileges are sufficient to trigger this flaw.
---
This issue has been addressed in following products:
Red Hat HPC Solution for RHEL 5
Via RHSA-2010:0635 https://rhn.redha
Bugzilla
CVE-2010-1644 CVE-2010-1645 CVE-2010-2092 Cacti v0.8.7f - three security fixes
bugzilla·2010-05-24·CVSS 4.3
CVE-2010-1644 [MEDIUM] CVE-2010-1644 CVE-2010-1645 CVE-2010-2092 Cacti v0.8.7f - three security fixes
CVE-2010-1644 CVE-2010-1645 CVE-2010-2092 Cacti v0.8.7f - three security fixes
Cacti upstream has released:
[1] http://www.cacti.net/release_notes_0_8_7f.php
latest v0.8.7 version, addressing three security flaws:
[A], MOPS-2010-023: Cacti Graph Viewer SQL Injection Vulnerability
[2] http://php-security.org/2010/05/13/mops-2010-023-cacti-graph-viewer-sql-injection-vulnerability/index.html
[3] http://www.vupen.com/english/advisories/2010/1204
Credit: The vulnerability was discovered by Stefan Esser as part
of the SQL Injection Marathon.
Upstream changeset:
[4] http://svn.cacti.net/viewvc?view=rev&revision=5920
[B], Cross-site scripting issues reported by VUPEN Security
(http://www.vupen.com)
[5] http://www.vupen.com/english/advisories/2010/1203
Credit: Vulnerabilities reported by Moham
http://php-security.org/2010/05/13/mops-2010-023-cacti-graph-viewer-sql-injection-vulnerability/index.htmlhttp://secunia.com/advisories/41041http://www.cacti.net/changelog.phphttp://www.debian.org/security/2010/dsa-2060http://www.vupen.com/english/advisories/2010/2132https://rhn.redhat.com/errata/RHSA-2010-0635.htmlhttp://php-security.org/2010/05/13/mops-2010-023-cacti-graph-viewer-sql-injection-vulnerability/index.htmlhttp://secunia.com/advisories/41041http://www.cacti.net/changelog.phphttp://www.debian.org/security/2010/dsa-2060http://www.vupen.com/english/advisories/2010/2132https://rhn.redhat.com/errata/RHSA-2010-0635.html
2010-05-27
Published