Описание
auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| cacti | fixed | 0.8.8g+ds1-1 | package | |
| cacti | fixed | 0.8.8b+dfsg-8+deb8u5 | jessie | package |
Примечания
http://svn.cacti.net/viewvc/cacti/tags/0.8.8g/docs/CHANGELOG?revision=7788&view=markup
http://bugs.cacti.net/view.php?id=2656
Upstream fix: http://svn.cacti.net/viewvc?view=rev&revision=7770
https://bugzilla.suse.com/show_bug.cgi?id=965930
https://www.openwall.com/lists/oss-security/2016/02/09/3
Only exploitable in non default setup
EPSS
Связанные уязвимости
auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
Уязвимость программного средства мониторинга сети Cacti, позволяющая нарушителю обойти существующие ограничения доступа
EPSS