Unrated severityNVD Advisory· Published Jun 17, 2015· Updated May 6, 2026
CVE-2015-4454
CVE-2015-4454
Description
SQL injection vulnerability in the get_hash_graph_template function in lib/functions.php in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via the graph_template_id parameter to graph_templates.php.
Affected products
4cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:23:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.cacti.net/release_notes_0_8_8d.phpnvdPatchVendor Advisory
- bugs.cacti.net/view.phpnvd
- lists.fedoraproject.org/pipermail/package-announce/2016-May/183449.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2016-May/183454.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2016-May/183919.htmlnvd
- www.debian.org/security/2015/dsa-3295nvd
- www.securityfocus.com/bid/75270nvd
News mentions
0No linked articles in our index yet.