7.5
CVSSv2

CVE-2010-2092

Published: 27/05/2010 Updated: 16/02/2012
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in graph.php in Cacti 0.8.7e and previous versions allows remote malicious users to execute arbitrary SQL commands via a crafted rra_id parameter in a GET request in conjunction with a valid rra_id value in a POST request or a cookie, which causes the POST or cookie value to bypass the validation routine, but inserts the $_GET value into the resulting query.

Vulnerable Product Search on Vulmon Subscribe to Product

cacti cacti 0.6.6

cacti cacti 0.6.7

cacti cacti 0.8.3

cacti cacti 0.8.3a

cacti cacti 0.8.6d

cacti cacti 0.8.6f

cacti cacti 0.8.7a

cacti cacti 0.8.7b

cacti cacti 0.6.4

cacti cacti 0.6.5

cacti cacti 0.8.2

cacti cacti 0.8.2a

cacti cacti 0.8.6b

cacti cacti 0.8.6c

cacti cacti 0.8.6k

cacti cacti 0.8.7

cacti cacti 0.6

cacti cacti 0.6.1

cacti cacti 0.6.8

cacti cacti 0.6.8a

cacti cacti 0.8.4

cacti cacti 0.8.5

cacti cacti 0.8.5a

cacti cacti 0.8.6g

cacti cacti 0.8.6h

cacti cacti 0.8.7c

cacti cacti 0.8.7d

cacti cacti 0.6.2

cacti cacti 0.6.3

cacti cacti 0.8

cacti cacti 0.8.1

cacti cacti 0.8.6

cacti cacti 0.8.6a

cacti cacti 0.8.6i

cacti cacti 0.8.6j

cacti cacti

cacti cacti 0.5

Vendor Advisories

Debian Bug report logs - #582691 Multiple security vulnerabilities in upstream package Package: cacti; Maintainer for cacti is Cacti Maintainer <pkg-cacti-maint@listsaliothdebianorg>; Source for cacti is src:cacti (PTS, buildd, popcon) Reported by: Rainbow Warrior <rnbwpnt@gmailcom> Date: Sat, 22 May 2010 20:15:0 ...