An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in data_debug.php allows remote authenticated attackers to execute arbitrary SQL commands via the site_id parameter. This can lead to remote code execution.
Dedicated Forum to help removing adware, malware, spyware, ransomware, trojans, viruses and more!
More Stories
OpenWRT Project Community Investigating Data Breach
‘Raindrop’ Is Latest Malware Tied to SolarWinds Hack
Microsoft Taking Additional Steps to Address Zerologon Flaw