[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2014-347 ---- cacti

ID: oval:org.secpod.oval:def:1600153Date: (C)2016-01-07   (M)2022-10-10
Class: PATCHFamily: unix




Cross-site request forgery vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users for unspecified commands, as demonstrated by requests that modify binary files, modify configurations, or add arbitrary users. Cross-site scripting vulnerability in cdef.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. lib/rrd.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified parameters. Multiple SQL injection vulnerabilities in graph_xport.php in Cacti 0.8.7g, 0.8.8b, and earlier allow remote attackers to execute arbitrary SQL commands via the graph_start, graph_end, graph_height, graph_width, graph_nolegend, print_source, local_graph_id, or rra_id parameter. lib/graph_export.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in unspecified vectors.

Platform:
Amazon Linux AMI
Product:
cacti
Reference:
ALAS-2014-347
CVE-2014-2327
CVE-2014-2326
CVE-2014-2709
CVE-2014-2708
CVE-2014-2328
CVE    5
CVE-2014-2328
CVE-2014-2708
CVE-2014-2709
CVE-2014-2326
...
CPE    13
cpe:/o:amazon:linux
cpe:/a:cacti:cacti:0.8.7
cpe:/a:cacti:cacti:0.8.8
cpe:/a:cacti:cacti:0.8.8a
...

© SecPod Technologies