Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

RaXnet Cacti Auth_Login.PHP SQL Injection Vulnerability

Solution:
It is reported that this vulnerability is addressed in the CVS release. This is not confirmed.

Gentoo has released advisory GLSA 200408-21 dealing with this issue. Users are advised to upgrade to the latest available version of Cacti using the following sequence of commands:

# emerge sync

# emerge -pv ">=net-analyzer/cacti-0.8.5a-r1"
# emerge ">=net-analyzer/cacti-0.8.5a-r1"

Please see the referenced Gentoo advisory for more information.

Gentoo has released an update to the above-mentioned advisory; the workaround section has been updated. Please see the referenced advisory for more information.

Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com <mailto:vuldb@securityfocus.com>.








 

Privacy Statement
Copyright 2008, SecurityFocus