Vulnerability Name: | CVE-2016-3659 (CCN-111978) | ||||||||||||||||||||||||||||||||
Assigned: | 2016-03-31 | ||||||||||||||||||||||||||||||||
Published: | 2016-03-31 | ||||||||||||||||||||||||||||||||
Updated: | 2016-12-01 | ||||||||||||||||||||||||||||||||
Summary: | SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote authenticated users to execute arbitrary SQL commands via the host_group_data parameter. | ||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 8.4 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C)
6.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:H/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
| ||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-89 | ||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||||||||||||||||||||||||||
References: | Source: MISC Type: Exploit http://bugs.cacti.net/view.php?id=2673 Source: MITRE Type: CNA CVE-2016-3659 Source: SUSE Type: UNKNOWN openSUSE-SU-2016:1328 Source: MISC Type: Exploit http://packetstormsecurity.com/files/136547/Cacti-0.8.8g-SQL-Injection.html Source: CCN Type: Full-Disclosure Mailing List, Thu, 31 Mar 2016 10:41:57 +0800 [CVE-2016-3659]Cacti graph_view.php SQL Injection Vulnerability Source: FULLDISC Type: Exploit 20160404 [CVE-2016-3659]Cacti graph_view.php SQL Injection Vulnerability Source: CCN Type: IBM Security Bulletin T1017908 (Platform RTM) Open Source Cacti vulnerability affects IBM Platform RTM (CVE-2016-3172, CVE-2016-3659) Source: BID Type: UNKNOWN 85806 Source: XF Type: UNKNOWN cacti-cve20163659-sql-injection(111978) Source: CCN Type: Packet Storm Security [04-05-2016] Cacti 0.8.8g SQL Injection Source: GENTOO Type: UNKNOWN GLSA-201607-05 | ||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
BACK |