UBUNTU-CVE-2014-2708

Source
https://ubuntu.com/security/CVE-2014-2708
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-2708.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2014-2708
Upstream
Withdrawn
2025-07-18T16:43:01Z
Published
2014-04-10T20:29:00Z
Modified
2025-07-16T07:31:53Z
Severity
  • Ubuntu - medium
Summary
[none]
Details

Multiple SQL injection vulnerabilities in graph_xport.php in Cacti 0.8.7g, 0.8.8b, and earlier allow remote attackers to execute arbitrary SQL commands via the (1) graph_start, (2) graph_end, (3) graph_height, (4) graph_width, (5) graph_nolegend, (6) print_source, (7) local_graph_id, or (8) rra_id parameter.

References

Affected packages

Ubuntu:14.04:LTS / cacti

Package

Name
cacti
Purl
pkg:deb/ubuntu/cacti@0.8.8b+dfsg-5?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.8.8b+dfsg-5

Affected versions

0.*
0.8.8b+dfsg-3

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "cacti",
            "binary_version": "0.8.8b+dfsg-5"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-2708.json"