Bug ID | 932266 |
---|---|
Summary | VUL-0: CVE-2015-0916: cacti: SQL injection vulnerability in graph.php before 0.8.6f allows remoteauthenticated users to... |
Classification | openSUSE |
Product | openSUSE Distribution |
Version | 13.2 |
Hardware | Other |
OS | Other |
Status | NEW |
Severity | Major |
Priority | P5 - None |
Component | Security |
Assignee | nix@opensuse.org |
Reporter | abergmann@suse.com |
QA Contact | qa-bugs@suse.de |
Found By | Security Response Team |
Blocker | --- |
CVE-2015-0916 SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote authenticated users to execute arbitrary SQL commands via the local_graph_id parameter, a different vulnerability than CVE-2007-6035. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0916 http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-0916.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0916 http://www.cvedetails.com/cve/CVE-2015-0916/ http://jvndb.jvn.jp/jvndb/JVNDB-2015-000064 http://www.cacti.net/release_notes_0_8_6f.php http://jvn.jp/en/jp/JVN18957556/index.html