Published: 20/11/2007 Updated: 29/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in graph.php in Cacti prior to 0.8.7a allows remote malicious users to execute arbitrary SQL commands via the local_graph_id parameter.

Vendor Advisories

Debian Bug report logs - #452085 cacti: CVE-2007-6035 sql injection Package: cacti; Maintainer for cacti is Cacti Maintainer <pkg-cacti-maint@listsaliothdebianorg>; Source for cacti is src:cacti (PTS, buildd, popcon) Reported by: Rafal Krypa <debian@icebergpl> Date: Tue, 20 Nov 2007 10:27:01 UTC Severity: grave ...
It was discovered that Cacti, a tool to monitor systems and networks, performs insufficient input sanitising, which allows SQL injection For the oldstable distribution (sarge) this problem has been fixed in version 086c-7sarge5 For the stable distribution (etch) this problem has been fixed in version 086i-32 For the unstable distribution (s ...