Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux - Get Memory Usage" setting to contain arbitrary commands.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2009-11-30 21:30
Updated : 2018-10-10 19:48
NVD link : CVE-2009-4112
Mitre link : CVE-2009-4112
CVE.ORG link : CVE-2009-4112
JSON object : View
Products Affected
cacti
- cacti
CWE
CWE-264
Permissions, Privileges, and Access Controls