Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Changzhao.Mao

Researcher fromDBAPPSecurity Ltd
#35345of 53,632
7.5Total CVSS
Vulnerabilities · 1
PT-2015-7777
7.5
2015-12-16
Cacti · Cacti · CVE-2015-8369
**Name of the Vulnerable Software and Affected Versions** Cacti versions 0.8.8f and earlier **Description** The issue allows remote attackers to execute arbitrary SQL commands. This is achieved by exploiting the `rra id` parameter in a properties action to the "graph.php" endpoint. **Recommendations** For versions 0.8.8f and earlier, update to a version later than 0.8.8f to resolve the issue. As a temporary workaround, consider restricting access to the "graph.php" endpoint to minimize the risk of exploitation. Avoid using the `rra id` parameter in the affected endpoint until the issue is resolved.