Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rwpv-9gq4-x5g3

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries.

A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries.

EPSS

Процентиль: 99%
0.81199
Высокий

7.2 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.2
ubuntu
больше 5 лет назад

A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries.

CVSS3: 7.2
nvd
больше 5 лет назад

A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries.

CVSS3: 7.2
debian
больше 5 лет назад

A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to ...

suse-cvrf
больше 5 лет назад

Security update for cacti, cacti-spine

EPSS

Процентиль: 99%
0.81199
Высокий

7.2 High

CVSS3

Дефекты

CWE-89