CVE-2011-4824
Vulnerability Summary
Timeline
Description
SQL injection vulnerability in auth_login.php in Cacti before 0.8.7h allows remote attackers to execute arbitrary SQL commands via the login_username parameter.
CVSS Metrics
- v2.0•HIGH•Score: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS Trends
Current EPSS score: 3.25%• Percentile: 87%
Techniques & Countermeasures
- CWE-89•Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Affected Systems
- Unknown•Cacti
≤ 0.8.7g | 0.5 | 0.6 | 0.6.1 | 0.6.2 | 0.6.3 | 0.6.4 | 0.6.5 | 0.6.6 | 0.6.7 | 0.6.8 | 0.6.8a | 0.8 | 0.8.1 | 0.8.2 | 0.8.2a | 0.8.3 | 0.8.3a | 0.8.4 | 0.8.5 | 0.8.5a | 0.8.6 | 0.8.6a | 0.8.6b | 0.8.6c | 0.8.6d | 0.8.6f | 0.8.6g | 0.8.6h | 0.8.6i | 0.8.6j | 0.8.6k | 0.8.7 | 0.8.7a | 0.8.7b | 0.8.7c | 0.8.7d | 0.8.7e
References (11)
- http://bugs.cacti.net/view.php?id=2062
- http://secunia.com/advisories/46876
- http://forums.cacti.net/viewtopic.php?f=21&t=44116
- http://www.securityfocus.com/bid/50671
- http://www.cacti.net/release_notes_0_8_7h.php
- http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069141.html
- http://svn.cacti.net/viewvc?view=rev&revision=6807
- http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069137.html
- http://secunia.com/advisories/44133
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71326
- http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069126.html