Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-31460

Опубликовано: 14 мая 2024
Источник: debian

Описание

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the SQL statement in `create_all_header_nodes()` function from `lib/api_automation.php` , finally resulting in SQL injection. Using SQL based secondary injection technology, attackers can modify the contents of the Cacti database, and based on the modified content, it may be possible to achieve further impact, such as arbitrary file reading, and even remote code execution through arbitrary file writing. Version 1.2.27 contains a patch for the issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cactifixed1.2.27+ds1-1package
cactifixed1.2.24+ds1-1+deb12u3bookwormpackage

Примечания

  • https://github.com/Cacti/cacti/security/advisories/GHSA-gj3f-p326-gh8r

  • https://github.com/Cacti/cacti/commit/8b516cb9a73322ad532231e74000c2ee097b495e

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the SQL statement in `create_all_header_nodes()` function from `lib/api_automation.php` , finally resulting in SQL injection. Using SQL based secondary injection technology, attackers can modify the contents of the Cacti database, and based on the modified content, it may be possible to achieve further impact, such as arbitrary file reading, and even remote code execution through arbitrary file writing. Version 1.2.27 contains a patch for the issue.

CVSS3: 6.5
nvd
больше 1 года назад

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the SQL statement in `create_all_header_nodes()` function from `lib/api_automation.php` , finally resulting in SQL injection. Using SQL based secondary injection technology, attackers can modify the contents of the Cacti database, and based on the modified content, it may be possible to achieve further impact, such as arbitrary file reading, and even remote code execution through arbitrary file writing. Version 1.2.27 contains a patch for the issue.

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость функции create_all_header_nodes() программного средства мониторинга сети Cacti, позволяющая нарушителю выполнять произвольные SQL-запросы

suse-cvrf
больше 1 года назад

Security update for cacti, cacti-spine

suse-cvrf
больше 1 года назад

Security update for cacti, cacti-spine