Cacti 'graph_xport.php' SQL Injection Vulnerability
BID:66555
Info
Cacti 'graph_xport.php' SQL Injection Vulnerability
| Bugtraq ID: | 66555 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2708 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 01 2014 12:00AM |
| Updated: | Nov 03 2015 07:15PM |
| Credit: | Murray McAllister |
| Vulnerable: |
Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Cacti Cacti 0.8.7 Cacti Cacti 0.8.7i Cacti Cacti 0.8.7h Cacti Cacti 0.8.7g Cacti Cacti 0.8.7f Cacti Cacti 0.8.7e Cacti Cacti 0.8.7d Cacti Cacti 0.8.7c Cacti Cacti 0.8.7b Cacti Cacti 0.8.7a |
| Not Vulnerable: | |
Discussion
Cacti 'graph_xport.php' SQL Injection Vulnerability
Cacti is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Cacti versions 0.8.8b and prior are vulnerable.
Cacti is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Cacti versions 0.8.8b and prior are vulnerable.
Exploit / POC
Cacti 'graph_xport.php' SQL Injection Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
Cacti 'graph_xport.php' SQL Injection Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].