[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195549

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2019-17357Date: (C)2020-01-22   (M)2023-12-22


Cacti through 1.2.7 is affected by a graphs.php?template_id= SQL injection vulnerability affecting how template identifiers are handled when a string and id composite value are used to identify the template type and id. An authenticated attacker can exploit this to extract data from the database, or an unauthenticated remote attacker could exploit this via Cross-Site Request Forgery.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 6.5CVSS Score : 4.0
Exploit Score: 2.8Exploit Score: 8.0
Impact Score: 3.6Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: LOWAuthentication: SINGLE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: NONE
Confidentiality: HIGHAvailability: NONE
Integrity: NONE 
Availability: NONE 
  
Reference:
GLSA-202003-40
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=947374
https://github.com/Cacti/cacti/issues/3025
https://www.darkmatter.ae/xen1thlabs/
openSUSE-SU-2020:0272
openSUSE-SU-2020:0284
openSUSE-SU-2020:0558
openSUSE-SU-2020:0565

CPE    1
cpe:/a:cacti:cacti
CWE    1
CWE-89
OVAL    4
oval:org.secpod.oval:def:604683
oval:org.secpod.oval:def:69940
oval:org.secpod.oval:def:61491
oval:org.secpod.oval:def:70496
...

© SecPod Technologies