Gentoo Linux Security Advisory GLSA 200701-23 – rgod discovered that the Cacti cmd.php and copy_cacti_user.php scripts do not properly control access to the command shell, and are remotely accessible by unauthenticated users. This allows SQL injection via cmd.php and copy_cacti_user.php URLs. Further, the results from the injected SQL query are not properly sanitized before being passed to a command shell. The vulnerabilities require that the register_argc_argv option is enabled, which is the Gentoo default. Also, a number of similar problems in other scripts were reported. Versions less than 0.8.6i-r1 are affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/54026/glsa-200701-23.txt
Source: https://packetstormsecurity.com/files/54026/Gentoo-Linux-Security-Advisory-200701-23.html

