Cacti'graph _ xport. php' SQL Injection Vulnerability
Release date:
Updated on:
Affected Systems:
Cacti <0.8.8b
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66555
Cacti is a database round robin (RRD) tool that helps you create images from database information. It has multiple Linux versions.
Cacti 0.8.8b and earlier versions have the SQL injection vulnerability in the 'graph _ xport. php' implementation. After successful exploitation, attackers can perform unauthorized database operations.
<* Source: Murray McAllister
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cacti
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://cacti.net/
Cacti details: click here
Cacti: click here
In RHEL6.4, the Cacti + Spine monitoring host is used to send mail alarms.
Use Cacti + Spine to monitor remote hosts in RHEL6.4
CentOS 5.5 complete installation of Cacti + Spine
Cacti construction document under CentOS 6
Detailed description of Cacti monitoring deployment under RHEL5.9
How to install Cacti in CentOS 6.3
Quick installation and configuration of Cacti in CentOS Linux