7.5
CVSSv2

CVE-2013-5589

Published: 29/08/2013 Updated: 30/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in cacti/host.php in Cacti 0.8.8b and previous versions allows remote malicious users to execute arbitrary SQL commands via the id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 7.0

cacti cacti 0.8.3

cacti cacti 0.8.3a

cacti cacti 0.8.6c

cacti cacti 0.8.6d

cacti cacti 0.8.7

cacti cacti 0.8.7a

cacti cacti 0.8.7h

cacti cacti 0.8.7i

cacti cacti 0.8

cacti cacti 0.8.1

cacti cacti 0.8.5a

cacti cacti 0.8.6

cacti cacti 0.8.6g

cacti cacti 0.8.6h

cacti cacti 0.8.7d

cacti cacti 0.8.7e

cacti cacti 0.8.2

cacti cacti 0.8.2a

cacti cacti 0.8.6a

cacti cacti 0.8.6b

cacti cacti 0.8.6i

cacti cacti 0.8.6j

cacti cacti 0.8.6k

cacti cacti 0.8.7f

cacti cacti 0.8.7g

cacti cacti

cacti cacti 0.8.8

cacti cacti 0.8.4

cacti cacti 0.8.5

cacti cacti 0.8.6e

cacti cacti 0.8.6f

cacti cacti 0.8.7b

cacti cacti 0.8.7c

cacti cacti 0.8.8a

opensuse opensuse 13.1

opensuse opensuse 13.2

Vendor Advisories

Two vulnerabilities were discovered in Cacti, a web interface for graphing of monitoring systems: CVE-2013-5588 install/indexphp and cacti/hostphp suffered from Cross-Site Scripting vulnerabilities CVE-2013-5589 cacti/hostphp contained an SQL injection vulnerability, allowing an attacker to execute SQL code on the database used ...
Various cross-site scripting (XSS) flaws (CVE-2013-5588, CVE-2014-5025, CVE-2014-5026) and various SQL injection flaws (CVE-2013-5589, CVE-2015-4342, CVE-2015-4634, CVE-2015-8377, CVE-2015-8604) were discovered affecting versions of Cacti prior to 088g Cross-site scripting (XSS) vulnerability in Cacti before 088d allows remote attackers to inj ...