LWN.net Logo

cacti: multiple vulnerabilities

Package(s):cacti CVE #(s):CVE-2006-6799
Created:January 1, 2007 Updated:January 26, 2007
Description: The network monitoring and graphing frontend Cacti has three vulnerabilities. The cmd.php script allows command line usage and is also installed in a web-accessible location. The cmd.php input is insufficiently sanitized, a passed-in URL can be used to inject arbitrary SQL code. The cmd.php script can be used by a remote attacker to execute arbitrary shell commands via improperly sanitized results from SQL queries.
Alerts:
Gentoo 200701-23 2007-01-26
Debian DSA-1250-1 2007-01-17
Mandriva MDKSA-2007:015 2007-01-15
SuSE SUSE-SA:2007:007 2007-01-12
OpenPKG OpenPKG-SA-2007.001 2007-01-01

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds