Vulnerability Name: | CVE-2016-3172 (CCN-111681) | ||||||||||||||||||||||||||||||||
Assigned: | 2016-03-22 | ||||||||||||||||||||||||||||||||
Published: | 2016-03-22 | ||||||||||||||||||||||||||||||||
Updated: | 2016-12-01 | ||||||||||||||||||||||||||||||||
Summary: | SQL injection vulnerability in tree.php in Cacti 0.8.8g and earlier allows remote authenticated users to execute arbitrary SQL commands via the parent_id parameter in an item_edit action. | ||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 8.4 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C)
6.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:H/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
| ||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-89 | ||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||||||||||||||||||||||||||
References: | Source: CCN Type: Cacti Web site Cacti SQL Injection Vulnerability Source: MISC Type: Exploit http://bugs.cacti.net/view.php?id=2667 Source: CCN Type: Cacti Website Cacti | The Complete RRDTool-based Graphing Solution Source: MITRE Type: CNA CVE-2016-3172 Source: SUSE Type: UNKNOWN openSUSE-SU-2016:1328 Source: CCN Type: oss-sec Mailing List, Thu, 10 Mar 2016 17:06:32 +0100 please assign CVE for cacti bug 2667: SQL Injection Vulnerability Source: CCN Type: oss-sec Mailing List, Tue, 15 Mar 2016 19:40:36 -0400 (EDT) Re: please assign CVE for cacti bug 2667: SQL Injection Vulnerability Source: CCN Type: IBM Security Bulletin T1017908 (Platform RTM) Open Source Cacti vulnerability affects IBM Platform RTM (CVE-2016-3172, CVE-2016-3659) Source: MLIST Type: UNKNOWN [oss-security] 20160310 please assign CVE for cacti bug 2667: SQL Injection Vulnerability Source: MLIST Type: UNKNOWN [oss-security] 20160315 Re: please assign CVE for cacti bug 2667: SQL Injection Vulnerability Source: BID Type: UNKNOWN 84324 Source: XF Type: UNKNOWN cacti-cve20163172-sql-injection(111681) Source: GENTOO Type: UNKNOWN GLSA-201607-05 | ||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
BACK |