7.5
CVSSv2

CVE-2013-1434

Published: 23/08/2013 Updated: 08/12/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in (1) api_poller.php and (2) utility.php in Cacti prior to 0.8.8b allow remote malicious users to execute arbitrary SQL commands via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

cacti cacti 0.8.7b

cacti cacti 0.8.7d

cacti cacti 0.8.7e

cacti cacti 0.8.6d

cacti cacti 0.8.6f

cacti cacti 0.8.5a

cacti cacti

cacti cacti 0.8.7i

cacti cacti 0.8.6

cacti cacti 0.8.6a

cacti cacti 0.8.6i

cacti cacti 0.8.6j

cacti cacti 0.8.7

cacti cacti 0.8.7a

cacti cacti 0.8.6b

cacti cacti 0.8.6c

cacti cacti 0.8.6k

cacti cacti 0.8.5

cacti cacti 0.8.8

cacti cacti 0.8.7g

cacti cacti 0.8.6e

cacti cacti 0.8.6g

cacti cacti 0.8.6h

Vendor Advisories

Two security issues (SQL injection and command line injection via SNMP settings) were found in Cacti, a web interface for graphing of monitoring systems For the oldstable distribution (squeeze), these problems have been fixed in version 087g-1+squeeze2 For the stable distribution (wheezy), these problems have been fixed in version 088a+dfsg- ...
(1) snmpphp and (2) rrdphp in Cacti before 088b allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors Multiple SQL injection vulnerabilities in (1) api_pollerphp and (2) utilityphp in Cacti before 088b allow remote attackers to execute arbitrary SQL commands via unspecified vectors ...