Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2005-2149 at MITRE


config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.

NVD CVSS v2 Base Score: 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)

SUSE information

SUSE Bugzilla entry: 95513 [RESOLVED]

SUSE Security Advisories: