Cacti CVE-2014-2327 Cross Site Request Forgery Vulnerability
BID:66392
Info
Cacti CVE-2014-2327 Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 66392 |
| Class: | Design Error |
| CVE: |
CVE-2014-2327 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 25 2014 12:00AM |
| Updated: | Nov 03 2015 07:15PM |
| Credit: | Deutsche Telekom CERT |
| Vulnerable: |
Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Cacti Cacti 0.8.7g |
| Not Vulnerable: | |
Discussion
Cacti CVE-2014-2327 Cross Site Request Forgery Vulnerability
Cacti is prone to a cross-site request-forgery vulnerability because it does not properly validate HTTP requests.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions. This may lead to further attacks.
Cacti 0.8.7g is vulnerable; other versions may also be affected.
Cacti is prone to a cross-site request-forgery vulnerability because it does not properly validate HTTP requests.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions. This may lead to further attacks.
Cacti 0.8.7g is vulnerable; other versions may also be affected.
Exploit / POC
Cacti CVE-2014-2327 Cross Site Request Forgery Vulnerability
Attackers can exploit this issue using browser. To exploit this issue the attacker needs to entice a user into following a malicious URI.
Attackers can exploit this issue using browser. To exploit this issue the attacker needs to entice a user into following a malicious URI.
Solution / Fix
Cacti CVE-2014-2327 Cross Site Request Forgery Vulnerability
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.