auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-560-1 cacti security update
Debian DLA Debian DLA DLA-560-2 cacti regression update
EUVD EUVD EUVD-2016-3397 auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: microfocus

Published:

Updated: 2024-08-05T23:24:48.943Z

Reserved: 2016-02-10T00:00:00

Link: CVE-2016-2313

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2016-04-13T17:59:11.977

Modified: 2025-04-12T10:46:40.837

Link: CVE-2016-2313

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses