CVE-2010-1431
cacti - missing input sanitising
EPSS 3.8%
Description
SQL injection vulnerability in templates_export.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via the export_item_id parameter.
How to fix CVE-2010-1431
To remediate CVE-2010-1431, upgrade the affected package to a fixed version below.
- Debian/cacti—upgrade to 0.8.7e-3 or later
- Debian/cacti—upgrade to 0.8.7b-2.1+lenny2 or later
Is CVE-2010-1431 being exploited?
Low — EPSS is 3.8%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 0.8.7e-3
- from 0, < 0.8.7b-2.1+lenny2