CVE-2011-4824

SQL injection vulnerability in auth_login.php in Cacti before 0.8.7h allows remote attackers to execute arbitrary SQL commands via the login_username parameter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.5:-:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.6:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.6.1:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.6.2:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.6.3:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.6.4:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.6.5:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.6.6:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.6.7:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.6.8:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.6.8a:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.1:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.2:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.2a:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.3:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.3a:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.4:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.5:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.5a:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.6:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.6a:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.6b:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.6c:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.6d:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.6f:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.6g:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.6h:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.6i:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.6j:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.6k:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.7:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.7a:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.7b:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.7c:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.7d:*:*:*:*:*:*:*
cpe:2.3:a:cacti:cacti:0.8.7e:*:*:*:*:*:*:*

History

21 Nov 2024, 01:33

Type Values Removed Values Added
References () http://bugs.cacti.net/view.php?id=2062 - () http://bugs.cacti.net/view.php?id=2062 -
References () http://forums.cacti.net/viewtopic.php?f=21&t=44116 - () http://forums.cacti.net/viewtopic.php?f=21&t=44116 -
References () http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069126.html - () http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069126.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069137.html - () http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069137.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069141.html - () http://lists.fedoraproject.org/pipermail/package-announce/2011-November/069141.html -
References () http://secunia.com/advisories/44133 - Vendor Advisory () http://secunia.com/advisories/44133 - Vendor Advisory
References () http://secunia.com/advisories/46876 - Vendor Advisory () http://secunia.com/advisories/46876 - Vendor Advisory
References () http://svn.cacti.net/viewvc?view=rev&revision=6807 - () http://svn.cacti.net/viewvc?view=rev&revision=6807 -
References () http://www.cacti.net/release_notes_0_8_7h.php - () http://www.cacti.net/release_notes_0_8_7h.php -
References () http://www.securityfocus.com/bid/50671 - () http://www.securityfocus.com/bid/50671 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/71326 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/71326 -

Information

Published : 2011-12-15 03:57

Updated : 2024-11-21 01:33


NVD link : CVE-2011-4824

Mitre link : CVE-2011-4824

CVE.ORG link : CVE-2011-4824


JSON object : View

Products Affected

cacti

  • cacti
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')