SQL injection vulnerability in the host_new_graphs function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via the cg_g parameter in a save action.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-386-1 cacti security update
Debian DSA Debian DSA DSA-3494-1 cacti security update
EUVD EUVD EUVD-2015-8482 SQL injection vulnerability in the host_new_graphs function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via the cg_g parameter in a save action.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00652}

epss

{'score': 0.0063}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T08:20:43.560Z

Reserved: 2015-12-17T00:00:00

Link: CVE-2015-8604

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2016-04-11T21:59:12.570

Modified: 2025-04-12T10:46:40.837

Link: CVE-2015-8604

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.