Cacti Multiple Input Validation Vulnerabilities
BID:27749
Info
Cacti Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 27749 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0786 CVE-2008-0785 CVE-2008-0784 CVE-2008-0783 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 12 2008 12:00AM |
| Updated: | May 21 2009 06:40PM |
| Credit: | Francesco "ascii" Ongaro and Antonio "s4tan" Parata are credited with the discovery of these vulnerabilities. |
| Vulnerable: |
S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc Red Hat Fedora 8 Red Hat Fedora 7 Planet Technology WSW-2401 0.8.6 h Planet Technology WSW-2401 0.8.6 g MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Cacti Cacti 0.8.7 Cacti Cacti 0.8.6 f Cacti Cacti 0.8.6 c Cacti Cacti 0.8.5 a Cacti Cacti 0.8.5 Cacti Cacti 0.8.4 Cacti Cacti 0.8.3 a Cacti Cacti 0.8.3 Cacti Cacti 0.8.2 a Cacti Cacti 0.8.2 Cacti Cacti 0.8.1 Cacti Cacti 0.8 Cacti Cacti 0.6.7 Cacti Cacti 0.8.7a Cacti Cacti 0.8.6j Cacti Cacti 0.8.6i |
| Not Vulnerable: |
Cacti Cacti 0.8.7b Cacti Cacti 0.8.6k |
Discussion
Cacti Multiple Input Validation Vulnerabilities
Cacti is prone to multiple unspecified input-validation vulnerabilities, including:
- Multiple cross-site scripting vulnerabilities
- Multiple SQL-injection vulnerabilities
- An HTTP response-splitting vulnerability.
Attackers may exploit these vulnerabilities to influence or misrepresent how web content is served, cached, or interpreted, to compromise the application, to access or modify data, to exploit vulnerabilities in the underlying database, or to execute arbitrary script code in the browser of an unsuspecting user.
These issues affect Cacti 0.8.7a and prior versions.
Cacti is prone to multiple unspecified input-validation vulnerabilities, including:
- Multiple cross-site scripting vulnerabilities
- Multiple SQL-injection vulnerabilities
- An HTTP response-splitting vulnerability.
Attackers may exploit these vulnerabilities to influence or misrepresent how web content is served, cached, or interpreted, to compromise the application, to access or modify data, to exploit vulnerabilities in the underlying database, or to execute arbitrary script code in the browser of an unsuspecting user.
These issues affect Cacti 0.8.7a and prior versions.
Exploit / POC
Cacti Multiple Input Validation Vulnerabilities
Attackers may exploit these issues through a browser.
To exploit the cross-site scripting and HTTP response-splitting issues, an attacker must entice an unsuspecting victim into visiting a malicious URI.
The following proof-of-concept URIs are available:
Attackers may exploit these issues through a browser.
To exploit the cross-site scripting and HTTP response-splitting issues, an attacker must entice an unsuspecting victim into visiting a malicious URI.
The following proof-of-concept URIs are available:
Solution / Fix
Cacti Multiple Input Validation Vulnerabilities
Solution:
The vendor has released an update to address these issues. Please see the references for more information.
Cacti Cacti 0.8.7a
Cacti Cacti 0.8.6j
Cacti Cacti 0.8.6i
Cacti Cacti 0.6.7
Cacti Cacti 0.8
Cacti Cacti 0.8.1
Cacti Cacti 0.8.2 a
Cacti Cacti 0.8.2
Cacti Cacti 0.8.3
Cacti Cacti 0.8.3 a
Cacti Cacti 0.8.4
Cacti Cacti 0.8.5
Cacti Cacti 0.8.5 a
Planet Technology WSW-2401 0.8.6 g
Cacti Cacti 0.8.6 f
Cacti Cacti 0.8.6 c
Planet Technology WSW-2401 0.8.6 h
Cacti Cacti 0.8.7
Solution:
The vendor has released an update to address these issues. Please see the references for more information.
Cacti Cacti 0.8.7a
-
Cacti cacti-0.8.7b.zip
http://www.cacti.net/downloads/cacti-0.8.7b.zip
Cacti Cacti 0.8.6j
-
Cacti cacti-0.8.6k.tar.gz
http://www.cacti.net/downloads/cacti-0.8.6k.tar.gz -
Cacti cacti-0.8.7b.zip
http://www.cacti.net/downloads/cacti-0.8.7b.zip
Cacti Cacti 0.8.6i
-
Cacti cacti-0.8.6k.tar.gz
http://www.cacti.net/downloads/cacti-0.8.6k.tar.gz -
Cacti cacti-0.8.7b.zip
http://www.cacti.net/downloads/cacti-0.8.7b.zip
Cacti Cacti 0.6.7
-
Cacti cacti-0.8.6k.tar.gz
http://www.cacti.net/downloads/cacti-0.8.6k.tar.gz -
Cacti cacti-0.8.7b.zip
http://www.cacti.net/downloads/cacti-0.8.7b.zip
Cacti Cacti 0.8
-
Cacti cacti-0.8.6k.tar.gz
http://www.cacti.net/downloads/cacti-0.8.6k.tar.gz -
Cacti cacti-0.8.7b.zip
http://www.cacti.net/downloads/cacti-0.8.7b.zip
Cacti Cacti 0.8.1
-
Cacti cacti-0.8.6k.tar.gz
http://www.cacti.net/downloads/cacti-0.8.6k.tar.gz -
Cacti cacti-0.8.7b.zip
http://www.cacti.net/downloads/cacti-0.8.7b.zip
Cacti Cacti 0.8.2 a
-
Cacti cacti-0.8.6k.tar.gz
http://www.cacti.net/downloads/cacti-0.8.6k.tar.gz -
Cacti cacti-0.8.7b.zip
http://www.cacti.net/downloads/cacti-0.8.7b.zip
Cacti Cacti 0.8.2
-
Cacti cacti-0.8.6k.tar.gz
http://www.cacti.net/downloads/cacti-0.8.6k.tar.gz -
Cacti cacti-0.8.7b.zip
http://www.cacti.net/downloads/cacti-0.8.7b.zip
Cacti Cacti 0.8.3
-
Cacti cacti-0.8.6k.tar.gz
http://www.cacti.net/downloads/cacti-0.8.6k.tar.gz -
Cacti cacti-0.8.7b.zip
http://www.cacti.net/downloads/cacti-0.8.7b.zip
Cacti Cacti 0.8.3 a
-
Cacti cacti-0.8.6k.tar.gz
http://www.cacti.net/downloads/cacti-0.8.6k.tar.gz -
Cacti cacti-0.8.7b.zip
http://www.cacti.net/downloads/cacti-0.8.7b.zip
Cacti Cacti 0.8.4
-
Cacti cacti-0.8.6k.tar.gz
http://www.cacti.net/downloads/cacti-0.8.6k.tar.gz -
Cacti cacti-0.8.7b.zip
http://www.cacti.net/downloads/cacti-0.8.7b.zip
Cacti Cacti 0.8.5
-
Cacti cacti-0.8.6k.tar.gz
http://www.cacti.net/downloads/cacti-0.8.6k.tar.gz -
Cacti cacti-0.8.7b.zip
http://www.cacti.net/downloads/cacti-0.8.7b.zip
Cacti Cacti 0.8.5 a
-
Cacti cacti-0.8.6k.tar.gz
http://www.cacti.net/downloads/cacti-0.8.6k.tar.gz -
Cacti cacti-0.8.7b.zip
http://www.cacti.net/downloads/cacti-0.8.7b.zip
Planet Technology WSW-2401 0.8.6 g
-
Cacti cacti-0.8.6k.tar.gz
http://www.cacti.net/downloads/cacti-0.8.6k.tar.gz -
Cacti cacti-0.8.7b.zip
http://www.cacti.net/downloads/cacti-0.8.7b.zip
Cacti Cacti 0.8.6 f
-
Cacti cacti-0.8.6k.tar.gz
http://www.cacti.net/downloads/cacti-0.8.6k.tar.gz -
Cacti cacti-0.8.7b.zip
http://www.cacti.net/downloads/cacti-0.8.7b.zip
Cacti Cacti 0.8.6 c
-
Cacti cacti-0.8.6k.tar.gz
http://www.cacti.net/downloads/cacti-0.8.6k.tar.gz -
Cacti cacti-0.8.7b.zip
http://www.cacti.net/downloads/cacti-0.8.7b.zip
Planet Technology WSW-2401 0.8.6 h
-
Cacti cacti-0.8.6k.tar.gz
http://www.cacti.net/downloads/cacti-0.8.6k.tar.gz -
Cacti cacti-0.8.7b.zip
http://www.cacti.net/downloads/cacti-0.8.7b.zip
Cacti Cacti 0.8.7
-
Cacti cacti-0.8.7b.zip
http://www.cacti.net/downloads/cacti-0.8.7b.zip
References
Cacti Multiple Input Validation Vulnerabilities
References:
References:
- 0001245: XSS-vulnerability (fgeek)
- Cacti 0.8.7b and 0.8.6k release - IMPORTANT SECURITY UPDATES (Cacti)
- Cacti Homepage (Cacti)
- Cacti Release Notes - 0.8.7b (Cacti)
- cacti -- Multiple security vulnerabilities have been discovered (Mario Sergio Candian
) - Cacti 0.8.7a Multiple Vulnerabilities (s4tan
)