HIGH
cacti: SQL injection vulnerability (BONSAI-2010-0104)
Published May 4, 2010
7.5
HIGHCVSS 2.0
EPSS 3.80%
Description
SQL injection vulnerability in templates_export.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via the export_item_id parameter.
Affected products
No data.
OR
- ≤ 0.8.7e
- 0.5
- 0.6
- 0.6.1
- 0.6.2
- 0.6.3
- 0.6.4
- 0.6.5
- 0.6.6
- 0.6.7
- 0.6.8
- 0.6.8a
- 0.8
- 0.8.1
- 0.8.2
- 0.8.2a
- 0.8.3
- 0.8.3a
- 0.8.4
- 0.8.5
- 0.8.5a
- 0.8.6
- 0.8.6a
- 0.8.6b
- 0.8.6c
- 0.8.6d
- 0.8.6f
- 0.8.6g
- 0.8.6h
- 0.8.6i
- 0.8.6j
- 0.8.6k
- 0.8.7
- 0.8.7a
- 0.8.7b
- 0.8.7c
- 0.8.7d
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (19)
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=578909 x_refsource_CONFIRMPatch
- http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html vendor-advisoryx_refsource_SUSE
- http://seclists.org/fulldisclosure/2010/Apr/272 mailing-listx_refsource_FULLDISC
- http://secunia.com/advisories/39568 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/39572 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/41041 third-party-advisoryx_refsource_SECUNIA
- http://www.cacti.net/downloads/patches/0.8.7e/sql_injection_template_export.patch x_refsource_CONFIRMPatch
- http://www.debian.org/security/2010/dsa-2039 vendor-advisoryx_refsource_DEBIAN
- http://www.exploit-db.com/sploits/Bonsai-SQL_Injection_in_Cacti.pdf x_refsource_MISC
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:092 vendor-advisoryx_refsource_MANDRIVA
- http://www.securityfocus.com/bid/39653 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2010/0986 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2010/1107 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2010/2132 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2010-1431 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=585401 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2010-1431
- https://rhn.redhat.com/errata/RHSA-2010-0635.html vendor-advisoryx_refsource_REDHAT
- https://www.cve.org/CVERecord?id=CVE-2010-1431
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 4, 2010
Updated Aug 7, 2024
Reserved Apr 15, 2010
Link CVE-2010-1431
CISA Vulnrichment
Updated n/a