Vulnerability Description
config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| The Cacti Group | Cacti | 0.8 |
References
- http://securitytracker.com/id?1014361
- http://sourceforge.net/mailarchive/forum.php?forum_id=10360&max_rows=25&style=flPatch
- http://www.cacti.net/downloads/patches/0.8.6e/cacti-0.8.6f_security.patchPatch
- http://www.debian.org/security/2005/dsa-764
- http://www.hardened-php.net/advisory-052005.phpPatchVendor Advisory
- http://www.securityfocus.com/archive/1/404040
- http://www.securityfocus.com/bid/14130
- http://www.vupen.com/english/advisories/2005/0951
- http://securitytracker.com/id?1014361
- http://sourceforge.net/mailarchive/forum.php?forum_id=10360&max_rows=25&style=flPatch
- http://www.cacti.net/downloads/patches/0.8.6e/cacti-0.8.6f_security.patchPatch
- http://www.debian.org/security/2005/dsa-764
- http://www.hardened-php.net/advisory-052005.phpPatchVendor Advisory
- http://www.securityfocus.com/archive/1/404040
- http://www.securityfocus.com/bid/14130
FAQ
What is CVE-2005-2149?
CVE-2005-2149 is a vulnerability with a CVSS score of 10.0 (HIGH). config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL in...
How severe is CVE-2005-2149?
CVE-2005-2149 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-2149?
Check the references section above for vendor advisories and patch information. Affected products include: The Cacti Group Cacti.