CVE-2015-8604
- EPSS 0.71%
- Veröffentlicht 11.04.2016 21:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in the host_new_graphs function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via the cg_g parameter in a save action.
CVE-2016-3659
- EPSS 0.59%
- Veröffentlicht 11.04.2016 15:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote authenticated users to execute arbitrary SQL commands via the host_group_data parameter.
CVE-2015-8369
- EPSS 0.5%
- Veröffentlicht 17.12.2015 19:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in include/top_graph_header.php in Cacti 0.8.8f and earlier allows remote attackers to execute arbitrary SQL commands via the rra_id parameter in a properties action to graph.php.
CVE-2015-8377
- EPSS 0.33%
- Veröffentlicht 15.12.2015 21:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in the host_new_graphs_save function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted serialized data in the selected_graphs_array parameter in a...
CVE-2015-4634
- EPSS 0.41%
- Veröffentlicht 11.08.2015 14:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in graphs.php in Cacti before 0.8.8e allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter.
CVE-2015-2967
- EPSS 0.32%
- Veröffentlicht 10.07.2015 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in settings.php in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2015-4454
- EPSS 0.64%
- Veröffentlicht 17.06.2015 18:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in the get_hash_graph_template function in lib/functions.php in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via the graph_template_id parameter to graph_templates.php.
CVE-2015-4342
- EPSS 3.76%
- Veröffentlicht 17.06.2015 18:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving a cdef id.
CVE-2015-2665
- EPSS 0.43%
- Veröffentlicht 17.06.2015 18:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2015-0916
- EPSS 0.35%
- Veröffentlicht 22.05.2015 00:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote authenticated users to execute arbitrary SQL commands via the local_graph_id parameter, a different vulnerability than CVE-2007-6035.