Cacti Graph.PHP SQL注入漏洞

漏洞信息详情

Cacti Graph.PHP SQL注入漏洞

漏洞简介

Cacti 0.8.7a之前的版本中graph.php存在SQL注入漏洞,远程攻击者借助local_graph_id参数执行任意SQL指令。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

Cacti Cacti 0.8.6j

Cacti Cacti 0.8.7a

http://www.cacti.net/download_cacti.php

Cacti Cacti 0.8.6i

Cacti Cacti 0.8.7a

http://www.cacti.net/download_cacti.php

Cacti Cacti 0.8

Cacti Cacti 0.8.7a

http://www.cacti.net/download_cacti.php

Cacti Cacti 0.8.1

Cacti Cacti 0.8.7a

http://www.cacti.net/download_cacti.php

Cacti Cacti 0.8.2 a

Cacti Cacti 0.8.7a

http://www.cacti.net/download_cacti.php

Cacti Cacti 0.8.2

Cacti Cacti 0.8.7a

http://www.cacti.net/download_cacti.php

Cacti Cacti 0.8.3

Cacti Cacti 0.8.7a

http://www.cacti.net/download_cacti.php

Cacti Cacti 0.8.3 a

Cacti Cacti 0.8.7a

http://www.cacti.net/download_cacti.php

Cacti Cacti 0.8.4

Cacti Cacti 0.8.7a

http://www.cacti.net/download_cacti.php

Cacti Cacti 0.8.5

Cacti Cacti 0.8.7a

http://www.cacti.net/download_cacti.php

Cacti Cacti 0.8.5 a

Cacti Cacti 0.8.7a

http://www.cacti.net/download_cacti.php

Planet Technology WSW-2401 0.8.6 g

Cacti Cacti 0.8.7a

http://www.cacti.net/download_cacti.php

Cacti Cacti 0.8.6 f

Cacti Cacti 0.8.7a

http://www.cacti.net/download_cacti.php

Cacti Cacti 0.8.6 c

Cacti Cacti 0.8.7a

http://www.cacti.net/download_cacti.php

Planet Technology WSW-2401 0.8.6 h

Cacti Cacti 0.8.7a

http://www.cacti.net/download_cacti.php

Cacti Cacti 0.8.7

Cacti Cacti 0.8.7a

http://www.cacti.net/download_cacti.php

参考网址

来源: www.cacti.net

链接:http://www.cacti.net/release_notes_0_8_7a.php

来源: SECUNIA

名称: 27719

链接:http://secunia.com/advisories/27719

来源: FEDORA

名称: FEDORA-2007-3683

链接:https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00794.html

来源: XF

名称: cacti-graph-sql-injection(38559)

链接:http://xforce.iss.net/xforce/xfdb/38559

来源: SECTRACK

名称: 1018982

链接:http://www.securitytracker.com/id?1018982

来源: BID

名称: 26487

链接:http://www.securityfocus.com/bid/26487

来源: SUSE

名称: SUSE-SR:2007:024

链接:http://www.novell.com/linux/security/advisories/2007_24_sr.html

来源: MANDRIVA

名称: MDKSA-2007:231

链接:http://www.mandriva.com/security/advisories?name=MDKSA-2007:231

来源: VUPEN

名称: ADV-2007-3911

链接:http://www.frsirt.com/english/advisories/2007/3911

来源: DEBIAN

名称: DSA-1418

链接:http://www.debian.org/security/2007/dsa-1418

来源: GENTOO

名称: GLSA-200712-02

链接:http://security.gentoo.org/glsa/glsa-200712-02.xml

来源: SECUNIA

名称: 27950

链接:http://secunia.com/advisories/27950

来源: SECUNIA

名称: 27891

链接:http://secunia.com/advisories/27891

来源: SECUNIA

名称: 27745

链接:http://secunia.com/advisories/27745

来源: MISC

链接:http://bugs.gentoo.org/show_bug.cgi?id=199509

来源: SECUNIA

名称: 27756

链接:http://secunia.com/advisories/27756

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享