RaXnet Cacti Input Filter Multiple SQL Injection Vulnerabilities
BID:14128
Info
RaXnet Cacti Input Filter Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 14128 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-1525 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 01 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Stefan Esser of the Hardened PHP Project is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Xoops Xoops 2.0.11 Xoops Xoops 2.0.10 Xoops Xoops 2.0.9 .3 Xoops Xoops 2.0.9 .2 Xoops Xoops 2.0.5 .2 Xoops Xoops 2.0.5 .1 Xoops Xoops 2.0.5 Xoops Xoops 2.0.3 Xoops Xoops 2.0.2 Xoops Xoops 2.0.1 Xoops Xoops 2.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 Raxnet Cacti 0.8.6 e Raxnet Cacti 0.8.6 d Raxnet Cacti 0.8.6 c Raxnet Cacti 0.8.6 b Raxnet Cacti 0.8.6 a Raxnet Cacti 0.8.6 Raxnet Cacti 0.8.5 a Raxnet Cacti 0.8.5 Raxnet Cacti 0.8.4 Raxnet Cacti 0.8.3 a Raxnet Cacti 0.8.3 Raxnet Cacti 0.8.2 a Raxnet Cacti 0.8.2 Raxnet Cacti 0.8.1 Raxnet Cacti 0.8 Raxnet Cacti 0.6.8 a Raxnet Cacti 0.6.8 Raxnet Cacti 0.6.7 Raxnet Cacti 0.6.6 Raxnet Cacti 0.6.5 Raxnet Cacti 0.6.4 Raxnet Cacti 0.6.3 Raxnet Cacti 0.6.2 Raxnet Cacti 0.6.1 Raxnet Cacti 0.6 Raxnet Cacti 0.5 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 |
| Not Vulnerable: |
Xoops Xoops 2.0.12 Raxnet Cacti 0.8.6 f |
Discussion
RaXnet Cacti Input Filter Multiple SQL Injection Vulnerabilities
RaXnet Cacti is prone to multiple SQL injection vulnerabilities. These issues are due to a bug in the input filters that lead to a failure in the application to properly sanitize user-supplied input, before using it in SQL queries.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
RaXnet Cacti is prone to multiple SQL injection vulnerabilities. These issues are due to a bug in the input filters that lead to a failure in the application to properly sanitize user-supplied input, before using it in SQL queries.
Successful exploitation could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.
Exploit / POC
RaXnet Cacti Input Filter Multiple SQL Injection Vulnerabilities
No exploit is required.
No exploit is required.
Solution / Fix
RaXnet Cacti Input Filter Multiple SQL Injection Vulnerabilities
Solution:
The vendor has addressed these issues in Cacti version 0.8.6f.
Conectiva Linux advisory CLSA-2005:978 is available to address various issues affecting cacti. Please see the referenced advisory for more information.
SUSE has released advisory SUSE-SR:2005:017 to address various issues. Please see the referenced advisory for more information.
Debian GNU/Linux has released advisory DSA 764-1 to address various issues in Cacti. Please see the referenced advisory for further information.
Raxnet Cacti 0.5
Raxnet Cacti 0.6
Raxnet Cacti 0.6.1
Raxnet Cacti 0.6.2
Raxnet Cacti 0.6.3
Raxnet Cacti 0.6.4
Raxnet Cacti 0.6.5
Raxnet Cacti 0.6.6
Raxnet Cacti 0.6.7
Raxnet Cacti 0.6.8
Raxnet Cacti 0.6.8 a
Raxnet Cacti 0.8
Raxnet Cacti 0.8.1
Raxnet Cacti 0.8.2 a
Raxnet Cacti 0.8.2
Raxnet Cacti 0.8.3 a
Raxnet Cacti 0.8.3
Raxnet Cacti 0.8.4
Raxnet Cacti 0.8.5
Raxnet Cacti 0.8.5 a
Raxnet Cacti 0.8.6
Raxnet Cacti 0.8.6 b
Raxnet Cacti 0.8.6 d
Raxnet Cacti 0.8.6 c
Raxnet Cacti 0.8.6 a
Raxnet Cacti 0.8.6 e
Xoops Xoops 2.0
Xoops Xoops 2.0.1
Xoops Xoops 2.0.10
Xoops Xoops 2.0.11
Xoops Xoops 2.0.2
Xoops Xoops 2.0.3
Xoops Xoops 2.0.5 .1
Xoops Xoops 2.0.5
Xoops Xoops 2.0.5 .2
Xoops Xoops 2.0.9 .2
Xoops Xoops 2.0.9 .3
Solution:
The vendor has addressed these issues in Cacti version 0.8.6f.
Conectiva Linux advisory CLSA-2005:978 is available to address various issues affecting cacti. Please see the referenced advisory for more information.
SUSE has released advisory SUSE-SR:2005:017 to address various issues. Please see the referenced advisory for more information.
Debian GNU/Linux has released advisory DSA 764-1 to address various issues in Cacti. Please see the referenced advisory for further information.
Raxnet Cacti 0.5
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6.1
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6.2
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6.3
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6.4
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6.5
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6.6
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6.7
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6.8
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.6.8 a
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.1
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.2 a
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.2
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.3 a
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.3
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.4
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.5
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.5 a
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.6
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.6 b
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.6 d
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.6 c
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.6 a
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Raxnet Cacti 0.8.6 e
-
Raxnet Cacti 0.8.6f
http://www.cacti.net/download_cacti.php
Xoops Xoops 2.0
-
Xoops Xoops-2.0.12.zip
http://prdownloads.sourceforge.net/xoops/Xoops-2.0.12.zip?download
Xoops Xoops 2.0.1
-
Xoops Xoops-2.0.12.zip
http://prdownloads.sourceforge.net/xoops/Xoops-2.0.12.zip?download
Xoops Xoops 2.0.10
-
Xoops Xoops-2.0.12.zip
http://prdownloads.sourceforge.net/xoops/Xoops-2.0.12.zip?download
Xoops Xoops 2.0.11
-
Xoops Xoops-2.0.12.zip
http://prdownloads.sourceforge.net/xoops/Xoops-2.0.12.zip?download
Xoops Xoops 2.0.2
-
Xoops Xoops-2.0.12.zip
http://prdownloads.sourceforge.net/xoops/Xoops-2.0.12.zip?download
Xoops Xoops 2.0.3
-
Xoops Xoops-2.0.12.zip
http://prdownloads.sourceforge.net/xoops/Xoops-2.0.12.zip?download
Xoops Xoops 2.0.5 .1
-
Xoops Xoops-2.0.12.zip
http://prdownloads.sourceforge.net/xoops/Xoops-2.0.12.zip?download
Xoops Xoops 2.0.5
-
Xoops Xoops-2.0.12.zip
http://prdownloads.sourceforge.net/xoops/Xoops-2.0.12.zip?download
Xoops Xoops 2.0.5 .2
-
Xoops Xoops-2.0.12.zip
http://prdownloads.sourceforge.net/xoops/Xoops-2.0.12.zip?download
Xoops Xoops 2.0.9 .2
-
Xoops Xoops-2.0.12.zip
http://prdownloads.sourceforge.net/xoops/Xoops-2.0.12.zip?download
Xoops Xoops 2.0.9 .3
-
Xoops Xoops-2.0.12.zip
http://prdownloads.sourceforge.net/xoops/Xoops-2.0.12.zip?download
References
RaXnet Cacti Input Filter Multiple SQL Injection Vulnerabilities
References:
References:
- Cacti Homepage (Cacti)
- Cacti Multiple SQL Injection Vulnerabilities (Hardened-PHP Project)
- Changelog 0.8.6f (Raxnet)
- CLSA-2005:978 - cacti (Conectiva)
- ProManager Homepage (Promanager)
- Security Release: XOOPS 2.0.12 (Xoops)
- XOOPS Web Site (XOOPS)
- Advisory 03/2005: Cacti Multiple SQL Injection Vulnerabilities [FIXED] (Stefan Esser
) - XOOPS 2.0.11 && Earlier Multiple Vulnerabilities (GulfTech Security Research
)