Boletines de Vulnerabilidades |
IBM Security Bulletin: Open Source Cacti vulnerability affects IBM Platform RTM (CVE-2016-3172, CVE-2016-3659) |
|
| Software afectado | IBM |
|
Cacti is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the tree.php script using the parent_id parameter, which could allow the attacker to view, add, modify or delete information in the back-end database. A remote attacker could send specially-crafted SQL statements to the graph_view.php script, which could allow the attacker to view, add, modify or delete information in the back-end database.CVE(s): CVE-2016-3172, CVE-2016-3659Affected More info: https://www.ibm.com/blogs/psirt/ibm-security-bulletin-open-source-cacti-vulnerability-affects-ibm-platform-rtm-cve-2016-3172-cve-2016-3659/ |
|














