|
Vulnerability Assessment & Network Security Forums |
|||||||||
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery. Home >> Browse Vulnerability Assessment Database >> Gentoo Local Security Checks >> [GLSA-200506-20] Cacti: Several vulnerabilities Vulnerability Assessment Details
|
[GLSA-200506-20] Cacti: Several vulnerabilities |
||
Cacti: Several vulnerabilities Detailed Explanation for this Vulnerability Assessment The remote host is affected by the vulnerability described in GLSA-200506-20 (Cacti: Several vulnerabilities) Cacti fails to properly sanitize input which can lead to SQL injection as well as PHP file inclusion. Impact A possible hacker could potentially exploit the file inclusion to execute arbitrary code with the permissions of the web server. A possible hacker could exploit the SQL injection to gain information from the database. Only systems with register_globals set to "On" are vulnerable to the file inclusion bugs. Gentoo Linux ships with register_globals set to "Off" by default. Workaround There is no known workaround at this time. References: http://www.cacti.net/release_notes_0_8_6e.php http://www.idefense.com/application/poi/display?id=267&type=vulnerabilities&flashstatus=false http://www.idefense.com/application/poi/display?id=266&type=vulnerabilities&flashstatus=false http://www.idefense.com/application/poi/display?id=265&type=vulnerabilities&flashstatus=false Solution: All Cacti users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=net-analyzer/cacti-0.8.6e" Note: Users with the vhosts USE flag set should manually use webapp-config to finalize the update. Network Security Threat Level: High Networks Security ID: Vulnerability Assessment Copyright: (C) 2005 Michel Arboi |
||
Cables, Connectors |
HP ProLiant Xeon E3-1220L V2 16 GB RAM 2.30 GHz MicroServer Gen8 NO DRIVES
$174.99
HP PROLIANT MICROSERVER MICRO SERVER HSTNS-5151 T4 Used.
$45.00
HP ProLiant HSTNS-5151 Micro Server 8GB RAM No Drives/Key/Caddies *READ*
$94.99
Supermicro Server Tower Xeon BOOTS E5-2620 v4 2.10GHz 64GB RAM NO HDD NO OS
$199.99
HPE ProLiant MicroServer Gen10 Plus v2 Ultra Micro Tower Server - 1 x Intel Xeon
$846.19
SuperMicro Server 505-2 Intel Atom 2.4GHz 8GB RAM SYS-5018A-FTN4 1U Rackmount
$202.49
Supermicro 5018A-FTN4 Rack Server - Black
$125.00
HP PROLIANT ML30 GEN9 INTEL XEON E3-1230 V6 3.50 GHz 16GB RAM SKU#55344
$164.99
1U Supermicro Server 10 Bay 2x Intel Xeon 3.3Ghz 8C 128GB RAM 480GB SSD 2x 10GBE
$297.00
2U 12 Bay SAS3 SuperMicro Server 6028U-TR4T+ W/ X10DRU-i+ Barebone 12 Caddy RAIL
$299.00
|
||
No Discussions have been posted on this vulnerability. |