Descriptionconfig.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.
Overall state of this security issue: Postponed
This issue is currently rated as having critical severity.
|National Vulnerability Database|
- SUSE-SR:2005:017, published Wed, 13 Jul 2005 11:00:00 +0000