SQL injection vulnerability in include/top_graph_header.php in Cacti 0.8.8f and earlier allows remote attackers to execute arbitrary SQL commands via the rra_id parameter in a properties action to graph.php.
References
Configurations
Information
Published : 2015-12-17 11:59
Updated : 2016-12-07 10:27
NVD link : CVE-2015-8369
Mitre link : CVE-2015-8369
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
cacti
- cacti