Unrated severityNVD Advisory· Published Jun 17, 2015· Updated Jun 17, 2026
CVE-2015-4454
CVE-2015-4454
Description
SQL injection vulnerability in the get_hash_graph_template function in lib/functions.php in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via the graph_template_id parameter to graph_templates.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*range: <=0.8.8c
- (no CPE)range: <0.8.8d
cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
7- www.cacti.net/release_notes_0_8_8d.phpnvdPatchVendor Advisory
- bugs.cacti.net/view.phpnvd
- lists.fedoraproject.org/pipermail/package-announce/2016-May/183449.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2016-May/183454.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2016-May/183919.htmlnvd
- www.debian.org/security/2015/dsa-3295nvd
- www.securityfocus.com/bid/75270nvd
News mentions
0No linked articles in our index yet.