what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 5 of 5 RSS Feed

CVE-2008-0785

Status Candidate

Overview

Multiple SQL injection vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote authenticated users to execute arbitrary SQL commands via the (1) graph_list parameter to graph_view.php, (2) leaf_id and id parameters to tree.php, (3) local_graph_id parameter to graph_xport.php, and (4) login_username parameter to index.php/login.

Related Files

Debian Linux Security Advisory 1569-3
Posted Jul 16, 2008
Authored by Debian | Site debian.org

Debian Security Advisory 1569-3 - Since the previous security update, the cacti package could no longer be rebuilt from the source package. This update corrects that problem. Note that this problem does not affect regular use of the provided binary packages (.deb).

tags | advisory
systems | linux, debian
advisories | CVE-2008-0783, CVE-2008-0785
SHA-256 | dc36fff9689e4aaf063e726c1168b13fa138e673807e06ed013c70027925613e
Debian Linux Security Advisory 1569-2
Posted May 6, 2008
Authored by Debian | Site debian.org

Debian Security Advisory 1569-2 - The original update for cacti unfortunately introduced a regression. Updated packages have been created to address this. It was discovered that Cacti, a systems and services monitoring frontend, performed insufficient input sanitising, leading to cross site scripting and SQL injection being possible.

tags | advisory, xss, sql injection
systems | linux, debian
advisories | CVE-2008-0783, CVE-2008-0785
SHA-256 | a25d71e2a484bbe0525e22985604072f8a0b56a19f2fc79a50227fb2af5045fc
Debian Linux Security Advisory 1569-1
Posted May 5, 2008
Authored by Debian | Site debian.org

Debian Security Advisory 1569-1 - It was discovered that Cacti, a systems and services monitoring frontend, performed insufficient input sanitizing, leading to cross site scripting and SQL injection being possible.

tags | advisory, xss, sql injection
systems | linux, debian
advisories | CVE-2008-0783, CVE-2008-0785
SHA-256 | a15748a6e26762a361015640d77f7b3ebb8ef1199a358015d04400e2751b1fda
Gentoo Linux Security Advisory 200803-18
Posted Mar 13, 2008
Authored by Gentoo | Site security.gentoo.org

Gentoo Linux Security Advisory GLSA 200803-18 - Multiple vulnerabilities were discovered in Cacti. Versions less than 0.8.7b are affected.

tags | advisory, vulnerability
systems | linux, gentoo
advisories | CVE-2008-0783, CVE-2008-0784, CVE-2008-0785, CVE-2008-0786
SHA-256 | 5d50dc8b0f98c436ce06069183ead19d0184212e2bf9f597effa4f50f1c1da86
Mandriva Linux Security Advisory 2008-052
Posted Feb 28, 2008
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory - A number of vulnerabilities were found in the Cacti program, including XSS vulnerabilities, SQL injection vulnerabilities, CRLF injection vulnerabilities, and information disclosure vulnerabilities.

tags | advisory, vulnerability, sql injection, info disclosure
systems | linux, mandriva
advisories | CVE-2008-0783, CVE-2008-0783, CVE-2008-0785, CVE-2008-0786
SHA-256 | 5fe42dda08bebbfce4119cc05d5717063b08de50a5bb53e8b466237a3065a788
Page 1 of 1
Back1Next

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    6 Files
  • 22
    Nov 22nd
    48 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    60 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close