CVE-2015-0916
published 2015-05-22CVE-2015-0916: SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote authenticated users to execute arbitrary SQL commands via the local_graph_id…
PriorityP433medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
1.08%
61.8th percentile
SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote authenticated users to execute arbitrary SQL commands via the local_graph_id parameter, a different vulnerability than CVE-2007-6035.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cacti | cacti | <= 0.8.6e | — |
| cacti | cacti | >= 0 < 0.8.6f-1 | 0.8.6f-1 |
| cacti | cacti | >= 0 < 0.8.6f-1 | 0.8.6f-1 |
| cacti | cacti | >= 0 < 0.8.6f-1 | 0.8.6f-1 |
| cacti | cacti | >= 0 < 0.8.6f-1 | 0.8.6f-1 |
| debian | cacti | < cacti 0.8.6f-1 (bookworm) | cacti 0.8.6f-1 (bookworm) |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xqwx-r7c6-p379: SQL injection vulnerability in graph
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2015-0916 [HIGH] CWE-89 GHSA-xqwx-r7c6-p379: SQL injection vulnerability in graph
SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote authenticated users to execute arbitrary SQL commands via the local_graph_id parameter, a different vulnerability than CVE-2007-6035.
OSV
CVE-2015-0916: SQL injection vulnerability in graph
osv·2015-05-22·CVSS 7.5
CVE-2015-0916 [HIGH] CVE-2015-0916: SQL injection vulnerability in graph
SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote authenticated users to execute arbitrary SQL commands via the local_graph_id parameter, a different vulnerability than CVE-2007-6035.
Debian
CVE-2015-0916: cacti - SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote au...
vendor_debian·2015·CVSS 7.5
CVE-2015-0916 [HIGH] CVE-2015-0916: cacti - SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote au...
SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote authenticated users to execute arbitrary SQL commands via the local_graph_id parameter, a different vulnerability than CVE-2007-6035.
Scope: local
bookworm: resolved (fixed in 0.8.6f-1)
bullseye: resolved (fixed in 0.8.6f-1)
forky: resolved (fixed in 0.8.6f-1)
sid: resolved (fixed in 0.8.6f-1)
trixie: resolved (fixed in 0.8.6f-1)
No detection rules found.
No writeups or analysis indexed.
2015-05-22
Published