{"id":"CVE-2015-0916","details":"SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote authenticated users to execute arbitrary SQL commands via the local_graph_id parameter, a different vulnerability than CVE-2007-6035.","modified":"2026-04-10T03:45:04.417804Z","published":"2015-05-22T00:59:02Z","references":[{"type":"ADVISORY","url":"http://jvn.jp/en/jp/JVN18957556/index.html"},{"type":"ADVISORY","url":"http://jvndb.jvn.jp/jvndb/JVNDB-2015-000064"},{"type":"ADVISORY","url":"http://www.cacti.net/release_notes_0_8_6f.php"},{"type":"FIX","url":"http://www.cacti.net/release_notes_0_8_6f.php"}],"schema_version":"1.7.5"}