漏洞信息详情
Cacti Graph.PHP SQL注入漏洞
- CNNVD编号:CNNVD-200711-298
- 危害等级: 高危
- CVE编号:
CVE-2007-6035
- 漏洞类型:
SQL注入
- 发布时间:
2007-11-20
- 威胁类型:
远程
- 更新时间:
2007-11-20
- 厂 商:
cacti - 漏洞来源:
The vendor reporte… -
漏洞简介
Cacti 0.8.7a之前的版本中graph.php存在SQL注入漏洞,远程攻击者借助local_graph_id参数执行任意SQL指令。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Cacti Cacti 0.8.6j
Cacti Cacti 0.8.7a
http://www.cacti.net/download_cacti.php
Cacti Cacti 0.8.6i
Cacti Cacti 0.8.7a
http://www.cacti.net/download_cacti.php
Cacti Cacti 0.8
Cacti Cacti 0.8.7a
http://www.cacti.net/download_cacti.php
Cacti Cacti 0.8.1
Cacti Cacti 0.8.7a
http://www.cacti.net/download_cacti.php
Cacti Cacti 0.8.2 a
Cacti Cacti 0.8.7a
http://www.cacti.net/download_cacti.php
Cacti Cacti 0.8.2
Cacti Cacti 0.8.7a
http://www.cacti.net/download_cacti.php
Cacti Cacti 0.8.3
Cacti Cacti 0.8.7a
http://www.cacti.net/download_cacti.php
Cacti Cacti 0.8.3 a
Cacti Cacti 0.8.7a
http://www.cacti.net/download_cacti.php
Cacti Cacti 0.8.4
Cacti Cacti 0.8.7a
http://www.cacti.net/download_cacti.php
Cacti Cacti 0.8.5
Cacti Cacti 0.8.7a
http://www.cacti.net/download_cacti.php
Cacti Cacti 0.8.5 a
Cacti Cacti 0.8.7a
http://www.cacti.net/download_cacti.php
Planet Technology WSW-2401 0.8.6 g
Cacti Cacti 0.8.7a
http://www.cacti.net/download_cacti.php
Cacti Cacti 0.8.6 f
Cacti Cacti 0.8.7a
http://www.cacti.net/download_cacti.php
Cacti Cacti 0.8.6 c
Cacti Cacti 0.8.7a
http://www.cacti.net/download_cacti.php
Planet Technology WSW-2401 0.8.6 h
Cacti Cacti 0.8.7a
http://www.cacti.net/download_cacti.php
Cacti Cacti 0.8.7
Cacti Cacti 0.8.7a
http://www.cacti.net/download_cacti.php
参考网址
来源: www.cacti.net
链接:http://www.cacti.net/release_notes_0_8_7a.php
来源: SECUNIA
名称: 27719
链接:http://secunia.com/advisories/27719
来源: FEDORA
名称: FEDORA-2007-3683
链接:https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00794.html
来源: XF
名称: cacti-graph-sql-injection(38559)
链接:http://xforce.iss.net/xforce/xfdb/38559
来源: SECTRACK
名称: 1018982
链接:http://www.securitytracker.com/id?1018982
来源: BID
名称: 26487
链接:http://www.securityfocus.com/bid/26487
来源: SUSE
名称: SUSE-SR:2007:024
链接:http://www.novell.com/linux/security/advisories/2007_24_sr.html
来源: MANDRIVA
名称: MDKSA-2007:231
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2007:231
来源: VUPEN
名称: ADV-2007-3911
链接:http://www.frsirt.com/english/advisories/2007/3911
来源: DEBIAN
名称: DSA-1418
链接:http://www.debian.org/security/2007/dsa-1418
来源: GENTOO
名称: GLSA-200712-02
链接:http://security.gentoo.org/glsa/glsa-200712-02.xml
来源: SECUNIA
名称: 27950
链接:http://secunia.com/advisories/27950
来源: SECUNIA
名称: 27891
链接:http://secunia.com/advisories/27891
来源: SECUNIA
名称: 27745
链接:http://secunia.com/advisories/27745
来源: MISC
链接:http://bugs.gentoo.org/show_bug.cgi?id=199509
来源: SECUNIA
名称: 27756