Novell Home

CVE-2005-2149

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2005-2149 at MITRE

Description

config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.

NVD CVSS v2 Base Score: 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)

Novell/SUSE information

Novell Bugzilla entry: 95513

SUSE Security Advisories:

© 2014 Novell