Cacti Multiple Command Injection Vulnerabilities
BID:61847
Info
Cacti Multiple Command Injection Vulnerabilities
| Bugtraq ID: | 61847 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-1435 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 06 2013 12:00AM |
| Updated: | Jan 22 2014 08:32AM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Planet Technology WSW-2401 0.8.6 h Planet Technology WSW-2401 0.8.6 g MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Cacti Cacti 0.8.7 Cacti Cacti 0.8.6 f Cacti Cacti 0.8.6 c Cacti Cacti 0.8.5 a Cacti Cacti 0.8.5 Cacti Cacti 0.8.4 Cacti Cacti 0.8.3 a Cacti Cacti 0.8.3 Cacti Cacti 0.8.2 a Cacti Cacti 0.8.2 Cacti Cacti 0.8.1 Cacti Cacti 0.8 Cacti Cacti 0.6.7 Cacti Cacti 0.8.7i Cacti Cacti 0.8.7h Cacti Cacti 0.8.7g Cacti Cacti 0.8.7f Cacti Cacti 0.8.7e Cacti Cacti 0.8.7d Cacti Cacti 0.8.7c Cacti Cacti 0.8.7b Cacti Cacti 0.8.7a Cacti Cacti 0.8.6k Cacti Cacti 0.8.6j Cacti Cacti 0.8.6i |
| Not Vulnerable: | |
Discussion
Cacti Multiple Command Injection Vulnerabilities
Cacti is prone to multiple command-injection vulnerabilities because the application fails to properly sanitize user-supplied input.
Exploiting these issues could allow an attacker to execute arbitrary commands in context of the vulnerable application.
Note: This issue was previously discussed in the Bid 61657 (Cacti Command Injection and SQL Injection Vulnerabilities), but its has been moved to Bid 61847 given its own record to better document it.
Versions prior to Cacti 0.8.8b are vulnerable.
Cacti is prone to multiple command-injection vulnerabilities because the application fails to properly sanitize user-supplied input.
Exploiting these issues could allow an attacker to execute arbitrary commands in context of the vulnerable application.
Note: This issue was previously discussed in the Bid 61657 (Cacti Command Injection and SQL Injection Vulnerabilities), but its has been moved to Bid 61847 given its own record to better document it.
Versions prior to Cacti 0.8.8b are vulnerable.
Exploit / POC
Cacti Multiple Command Injection Vulnerabilities
Attackers can use readily available tools to exploit these issues.
Attackers can use readily available tools to exploit these issues.
Solution / Fix
Cacti Multiple Command Injection Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.