LWN.net Logo

cacti: command execution

Package(s):cacti CVE #(s):CVE-2011-4824
Created:January 9, 2012 Updated:January 23, 2012
Description: From the CVE entry:

SQL injection vulnerability in auth_login.php in Cacti before 0.8.7h allows remote attackers to execute arbitrary SQL commands via the login_username parameter.

Alerts:
Debian DSA-2384-1 2012-01-09
Mandriva MDVSA-2012:010 2012-01-20
Debian DSA-2384-2 2012-02-04

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds