Description
|
|
Multiple vulnerabilities have been identified in Cacti, which could be exploited to compromise a vulnerable web server.
The first issue is caused by an input validation error in the "graph.php" script when processing the "rra_id" parameter, which could be exploited by malicious people to conduct SQL injection attacks.
The second vulnerability is caused by input validation errors when creating or editing a Device or a Graph Template, which could be exploited by attackers to inject and execute arbitrary shell commands with the privileges of the web server.
|