First published: Thu Feb 14 2008(Updated: )
graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allows remote attackers to obtain the full path via an invalid local_graph_id parameter and other unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti | =0.8.7 | |
Cacti | =0.8.5a | |
Cacti | =0.8.3 | |
Cacti | =0.8.2 | |
Cacti | =0.8.5 | |
Cacti | =0.8.7a | |
Cacti | =0.8.6f | |
Cacti | =0.8.6j | |
Cacti | =0.8 | |
Cacti | =0.8.6i | |
Cacti | =0.6.7 | |
Cacti | =0.8.1 | |
Cacti | =0.8.4 | |
Cacti | =0.8.6c | |
Cacti | =0.8.2a | |
Cacti | =0.8.3a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0784 is classified as a medium severity vulnerability as it allows attackers to discover the full path of the installation.
To fix CVE-2008-0784, update to Cacti versions 0.8.7b or later, or 0.8.6k or later.
CVE-2008-0784 affects Cacti versions 0.8.2, 0.8.3, 0.8.4, 0.8.5, 0.8.5a, 0.8.6c, 0.8.6f, 0.8.6j, 0.8.6i, 0.8.7, and 0.8.7a.
CVE-2008-0784 enables remote attackers to obtain the full path of the Cacti installation through improper handling of the local_graph_id parameter.
The main mitigation strategy for CVE-2008-0784 is to ensure that Cacti installations are regularly updated to patch known vulnerabilities.