auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://security.gentoo.org/glsa/201607-05 | vendor advisory |
http://www.securitytracker.com/id/1037745 | vdb entry |
http://lists.opensuse.org/opensuse-updates/2016-02/msg00078.html | vendor advisory |
http://www.cacti.net/release_notes_0_8_8g.php | |
http://lists.opensuse.org/opensuse-updates/2016-02/msg00077.html | vendor advisory |
http://lists.opensuse.org/opensuse-updates/2016-02/msg00080.html | vendor advisory |
http://bugs.cacti.net/view.php?id=2656 | |
https://security.gentoo.org/glsa/201711-10 | vendor advisory |