CVE-2007-6035

Publication date 20 November 2007

Last updated 24 July 2024


Ubuntu priority

SQL injection vulnerability in graph.php in Cacti before 0.8.7a allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter.

Status

Package Ubuntu Release Status
cacti 8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
7.10 gutsy
Fixed 0.8.6j-1.1ubuntu0.1
7.04 feisty
Fixed 0.8.6i-3ubuntu0.1
6.10 edgy Ignored end of life, was pending
6.06 LTS dapper
Fixed 0.8.6h-1ubuntu3.4

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
cacti