Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux - Get Memory Usage" setting to contain arbitrary commands.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/508129/100/0/threaded | mailing list |
http://archives.neohapsis.com/archives/fulldisclosure/2009-11/0292.html | mailing list exploit |
http://www.openwall.com/lists/oss-security/2009/11/30/2 | mailing list |
http://www.openwall.com/lists/oss-security/2009/11/26/1 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/54473 | vdb entry |
http://www.securityfocus.com/bid/37137 | vdb entry exploit |
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00001.html | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00005.html | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00042.html | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00048.html | vendor advisory |