Descriptionconfig.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.
Overall state of this security issue: Resolved
This issue is currently rated as having critical severity.
|National Vulnerability Database|
SUSE Security Advisories:
- SUSE-SR:2005:017, published Wed, 13 Jul 2005 11:00:00 +0000
SUSE Timeline for this CVECVE page created: Fri Jun 28 01:35:26 2013
CVE page last modified: Fri Oct 7 12:45:31 2022