[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256148

 
 

909

 
 

199106

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2024-1915 --- cacti

ID: oval:org.secpod.oval:def:1601881Date: (C)2024-03-05   (M)2024-06-17
Class: PATCHFamily: unix




Cacti provides an operational monitoring and fault management framework. Version 1.2.25 has a Blind SQL Injection vulnerability within the SNMP Notification Receivers feature in the file 'managers.php'. An authenticated attacker with the "Settings/Utilities" permission can send a crafted HTTP GET request to the endpoint '/cacti/managers.php' with an SQLi payload in the 'selected_graphs_array' HTTP GET parameter. As of time of publication, no patched versions exist

Platform:
Amazon Linux AMI
Product:
cacti
Reference:
ALAS-2024-1915
CVE-2023-51448
CVE    1
CVE-2023-51448

© SecPod Technologies