CVE-2020-14295
Summary
| CVE | CVE-2020-14295 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-17 14:15:00 UTC |
| Updated | 2023-11-07 03:17:00 UTC |
| Description | A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Cacti 1.2.12 SQL Injection / Remote Code Execution ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| [security-announce] openSUSE-SU-2020:1106-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| [security-announce] openSUSE-SU-2020:1060-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
|
| SQL Injection vulnerability due to input validation failure when editing colors (CVE-2020-14295) · Issue #3622 · Cacti/cacti · GitHub |
MISC |
github.com |
Exploit, Issue Tracking, Third Party Advisory |
| Cacti: Multiple vulnerabilities (GLSA 202007-03) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 32 Update: cacti-1.2.13-1.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 31 Update: cacti-spine-1.2.13-1.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 31 Update: cacti-spine-1.2.13-1.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Cacti 1.2.12 SQL Injection / Remote Command Execution ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| [SECURITY] Fedora 32 Update: cacti-1.2.13-1.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 501529 Alpine Linux Security Update for cacti
- 504593 Alpine Linux Security Update for cacti
- 690483 Free Berkeley Software Distribution (FreeBSD) Security Update for cacti (cd2dc126-cfe4-11ea-9172-4c72b94353b5)