CVE-2014-2708
published 2014-04-10CVE-2014-2708: Multiple SQL injection vulnerabilities in graph_xport.php in Cacti 0.8.7g, 0.8.8b, and earlier allow remote attackers to execute arbitrary SQL commands via the…
PriorityP344high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.99%
78.6th percentile
Multiple SQL injection vulnerabilities in graph_xport.php in Cacti 0.8.7g, 0.8.8b, and earlier allow remote attackers to execute arbitrary SQL commands via the (1) graph_start, (2) graph_end, (3) graph_height, (4) graph_width, (5) graph_nolegend, (6) print_source, (7) local_graph_id, or (8) rra_id parameter.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cacti | cacti | — | — |
| cacti | cacti | >= 0 < 0.8.8b+dfsg-4 | 0.8.8b+dfsg-4 |
| cacti | cacti | >= 0 < 0.8.8b+dfsg-4 | 0.8.8b+dfsg-4 |
| cacti | cacti | >= 0 < 0.8.8b+dfsg-4 | 0.8.8b+dfsg-4 |
| cacti | cacti | >= 0 < 0.8.8b+dfsg-4 | 0.8.8b+dfsg-4 |
| debian | cacti | < cacti 0.8.8b+dfsg-4 (bookworm) | cacti 0.8.8b+dfsg-4 (bookworm) |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8975-c5xr-xccw: Multiple SQL injection vulnerabilities in graph_xport
ghsa_unreviewed·2022-05-17
CVE-2014-2708 [HIGH] CWE-89 GHSA-8975-c5xr-xccw: Multiple SQL injection vulnerabilities in graph_xport
Multiple SQL injection vulnerabilities in graph_xport.php in Cacti 0.8.7g, 0.8.8b, and earlier allow remote attackers to execute arbitrary SQL commands via the (1) graph_start, (2) graph_end, (3) graph_height, (4) graph_width, (5) graph_nolegend, (6) print_source, (7) local_graph_id, or (8) rra_id parameter.
OSV
CVE-2014-2708: Multiple SQL injection vulnerabilities in graph_xport
osv·2014-04-10·CVSS 7.5
CVE-2014-2708 [HIGH] CVE-2014-2708: Multiple SQL injection vulnerabilities in graph_xport
Multiple SQL injection vulnerabilities in graph_xport.php in Cacti 0.8.7g, 0.8.8b, and earlier allow remote attackers to execute arbitrary SQL commands via the (1) graph_start, (2) graph_end, (3) graph_height, (4) graph_width, (5) graph_nolegend, (6) print_source, (7) local_graph_id, or (8) rra_id parameter.
Debian
CVE-2014-2708: cacti - Multiple SQL injection vulnerabilities in graph_xport.php in Cacti 0.8.7g, 0.8.8...
vendor_debian·2014·CVSS 7.5
CVE-2014-2708 [HIGH] CVE-2014-2708: cacti - Multiple SQL injection vulnerabilities in graph_xport.php in Cacti 0.8.7g, 0.8.8...
Multiple SQL injection vulnerabilities in graph_xport.php in Cacti 0.8.7g, 0.8.8b, and earlier allow remote attackers to execute arbitrary SQL commands via the (1) graph_start, (2) graph_end, (3) graph_height, (4) graph_width, (5) graph_nolegend, (6) print_source, (7) local_graph_id, or (8) rra_id parameter.
Scope: local
bookworm: resolved (fixed in 0.8.8b+dfsg-4)
bullseye: resolved (fixed in 0.8.8b+dfsg-4)
forky: resolved (fixed in 0.8.8b+dfsg-4)
sid: resolved (fixed in 0.8.8b+dfsg-4)
trixie: resolved (fixed in 0.8.8b+dfsg-4)
No detection rules found.
Bugzilla
CVE-2014-2709 CVE-2014-2708 cacti: command injection issues fixed in bug#0002405 [fedora-all]
bugzilla·2014-04-04·CVSS 7.5
CVE-2014-2709 [HIGH] CVE-2014-2709 CVE-2014-2708 cacti: command injection issues fixed in bug#0002405 [fedora-all]
CVE-2014-2709 CVE-2014-2708 cacti: command injection issues fixed in bug#0002405 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note
Bugzilla
CVE-2014-2708 CVE-2014-2709 cacti: command injection issues fixed in bug#0002405
bugzilla·2014-04-04·CVSS 7.5
CVE-2014-2708 [HIGH] CVE-2014-2708 CVE-2014-2709 cacti: command injection issues fixed in bug#0002405
CVE-2014-2708 CVE-2014-2709 cacti: command injection issues fixed in bug#0002405
Cacti bug#0002405 includes fixes for SQL injection and shell escaping (which could lead to arbitrary command execution). Fixes are available from:
http://svn.cacti.net/viewvc?view=rev&revision=7439
CVE-2014-2708 is for the SQL injection issues in graph_xport.php.
CVE-2014-2709 is for the shell escaping issues in lib/rrd.php
References:
http://seclists.org/oss-sec/2014/q2/15
Discussion:
Created cacti tracking bugs for this issue:
Affects: fedora-all [bug 1084259]
Affects: epel-all [bug 1084260]
---
cacti-0.8.8b-5.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report.
---
cacti-0.8.8b-5.fc20 has been pushed to the Fedora 20 stab
Bugzilla
CVE-2014-2709 CVE-2014-2708 cacti: command injection issues fixed in bug#0002405 [epel-all]
bugzilla·2014-04-04·CVSS 7.5
CVE-2014-2709 [HIGH] CVE-2014-2709 CVE-2014-2708 cacti: command injection issues fixed in bug#0002405 [epel-all]
CVE-2014-2709 CVE-2014-2708 cacti: command injection issues fixed in bug#0002405 [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please n
http://bugs.cacti.net/view.php?id=2405http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131821.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-April/131842.htmlhttp://seclists.org/oss-sec/2014/q2/15http://seclists.org/oss-sec/2014/q2/2http://secunia.com/advisories/57647http://secunia.com/advisories/59203http://svn.cacti.net/viewvc?view=rev&revision=7439http://www.debian.org/security/2014/dsa-2970http://www.securityfocus.com/bid/66555https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742768https://bugzilla.redhat.com/show_bug.cgi?id=1084258https://exchange.xforce.ibmcloud.com/vulnerabilities/92278https://security.gentoo.org/glsa/201509-03http://bugs.cacti.net/view.php?id=2405http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131821.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-April/131842.htmlhttp://seclists.org/oss-sec/2014/q2/15http://seclists.org/oss-sec/2014/q2/2http://secunia.com/advisories/57647http://secunia.com/advisories/59203http://svn.cacti.net/viewvc?view=rev&revision=7439http://www.debian.org/security/2014/dsa-2970http://www.securityfocus.com/bid/66555https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742768https://bugzilla.redhat.com/show_bug.cgi?id=1084258https://exchange.xforce.ibmcloud.com/vulnerabilities/92278https://security.gentoo.org/glsa/201509-03
2014-04-10
Published