7.5
CVSSv2

CVE-2010-1431

Published: 04/05/2010 Updated: 16/02/2012
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in templates_export.php in Cacti 0.8.7e and previous versions allows remote malicious users to execute arbitrary SQL commands via the export_item_id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

cacti cacti 0.8.5a

cacti cacti 0.8.5

cacti cacti 0.8.7

cacti cacti

cacti cacti 0.8.6d

cacti cacti 0.8.6b

cacti cacti 0.6.3

cacti cacti 0.6.2

cacti cacti 0.6.7

cacti cacti 0.8

cacti cacti 0.8.4

cacti cacti 0.8.3a

cacti cacti 0.8.6h

cacti cacti 0.8.6g

cacti cacti 0.6.5

cacti cacti 0.6.4

cacti cacti 0.8.6j

cacti cacti 0.8.7a

cacti cacti 0.8.6f

cacti cacti 0.8.6c

cacti cacti 0.8.7d

cacti cacti 0.8.7c

cacti cacti 0.8.6a

cacti cacti 0.8.6

cacti cacti 0.6.1

cacti cacti 0.6

cacti cacti 0.8.6i

cacti cacti 0.8.1

cacti cacti 0.8.2

cacti cacti 0.8.3

cacti cacti 0.8.2a

cacti cacti 0.8.7b

cacti cacti 0.8.6k

cacti cacti 0.6.8a

cacti cacti 0.6.8

cacti cacti 0.6.6

cacti cacti 0.5

Exploits

CVSSv2 Score: 9 (AV:N/AC:L/Au:S/C:C/I:C/A:C) A Vulnerability has been discovered in Cacti, which can be exploited by any user to conduct SQL Injection attacks Input passed via the “export_item_id” parameter to “templates_exportphp” script is not properly sanitized before being used in a SQL query This can be exploited to manipulate SQL q ...