CVE-2005-2149
Publication date 6 July 2005
Last updated 24 July 2024
Ubuntu priority
config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.
Status
Package | Ubuntu Release | Status |
---|---|---|
cacti | 7.04 feisty |
Fixed 0.8.6i-3
|
6.10 edgy |
Fixed 0.8.6h-3ubuntu0.1
|
|
6.06 LTS dapper |
Fixed 0.8.6h-1ubuntu3.1
|