HTTP: Cacti Group Cacti graphs SQL Injection

This signature detects attempts to exploit a known vulnerability against Cacti. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

Cacti through 1.2.7 is affected by a graphs.php?template_id= SQL injection vulnerability affecting how template identifiers are handled when a string and id composite value are used to identify the template type and id. An authenticated attacker can exploit this to extract data from the database, or an unauthenticated remote attacker could exploit this via Cross-Site Request Forgery.

Affected Products

Cacti cacti

Short Name
HTTP:SQL:INJ:CACTI-TMPLTID-SQLI
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2019-17357 CVE-2020-14295 CVE-2023-39361 CVE-2023-49085 Cacti Group Injection SQL graphs
Release Date
02/11/2020
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3668
False Positive
Unknown
Vendors

Cacti

CVSS Score

6.5

4.0

Found a potential security threat?