cacti
Page content
- Author: Miklos Vajna
- Vulnerable: 0.8.7e-1
- Unaffected: 0.8.7e-2locris1
A vulnerability has been reported in Cacti, which can be exploited by malicious users to conduct SQL injection attacks. Input passed via the “export_item_id” parameter to templates_export.php is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Successful exploitation requires that the attacker is allowed to export templates.
- Bug Tracker URL: http://bugs.frugalware.org/task/4193
CVEs:
- No CVE yet, see http://seclists.org/fulldisclosure/2010/Apr/272.