Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.807562
Kategorie:Web application abuses
Titel:Cacti Multiple SQL Injection And Security Bypass Vulnerabilities-01 Apr16 (Linux)
Zusammenfassung:This host is installed with Cacti and is; prone to multiple sql injection and a security bypass vulnerabilities.
Beschreibung:Summary:
This host is installed with Cacti and is
prone to multiple sql injection and a security bypass vulnerabilities.

Vulnerability Insight:
Multiple flaws exist due to:

- An insufficient validation of user supplied input via parameter 'cg_g' in the host_new_graphs function
graphs_new.php script.

- An insufficient validation of user supplied input via parameter 'rra_id' in a properties action to graph.php
script.

- An insufficient validation of user supplied input via parameter 'selected_graphs_array' in the
host_new_graphs_save function in graphs_new.php script.

Vulnerability Impact:
Successful exploitation will allow remote attacker to execute arbitrary SQL
commands and to bypass intended access restrictions.

Affected Software/OS:
Cacti version 0.8.8f and earlier on Linux.

Solution:
Upgrade to version 0.8.8g or later.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2015-8604
Debian Security Information: DSA-3494 (Google Search)
http://www.debian.org/security/2016/dsa-3494
http://seclists.org/fulldisclosure/2016/Jan/16
https://security.gentoo.org/glsa/201607-05
http://bugs.cacti.net/view.php?id=2652
http://packetstormsecurity.com/files/135191/Cacti-0.8.8f-graphs_new.php-SQL-Injection.html
http://www.openwall.com/lists/oss-security/2016/01/04/8
http://www.openwall.com/lists/oss-security/2016/01/04/9
http://www.securitytracker.com/id/1034573
Common Vulnerability Exposure (CVE) ID: CVE-2015-8369
Debian Security Information: DSA-3423 (Google Search)
http://www.debian.org/security/2015/dsa-3423
http://seclists.org/fulldisclosure/2015/Dec/8
http://bugs.cacti.net/view.php?id=2646
http://packetstormsecurity.com/files/134724/Cacti-0.8.8f-SQL-Injection.html
http://www.securitytracker.com/id/1034497
Common Vulnerability Exposure (CVE) ID: CVE-2015-8377
http://seclists.org/fulldisclosure/2015/Dec/57
http://www.securitytracker.com/id/1034498
CopyrightCopyright (C) 2016 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.